2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10307MEDIUM5.5An issue has been discovered in GitLab EE/CE affecting all versions from 12.10 before 17.8.6, 17.9 before 17.9.3, and 17...
CVE-2024-49601CRITICAL9.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-13939HIGH7.5String::Compare::ConstantTime for Perl through 0.321 is vulnerable to timing attacks that allow an attacker to guess the...
CVE-2024-49565HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49564HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-49563HIGH7.8Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2024-55070LOW3.1A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allo...
CVE-2024-55073HIGH7.6A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-55072MEDIUM5.4A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows ...
CVE-2024-12905HIGH7.5An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted ...
CVE-2024-58091MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/fbdev-dma: Add shadow buffering for deferred I/...
CVE-2024-58090MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched/core: Prevent rescheduling when interrupts ar...
CVE-2024-56469MEDIUM6.3IBM UrbanCode Deploy (UCD) 7.1 through 7.1.2.22, 7.2 through 7.2.3.15, and 7.3 through 7.3.2.10 / IBM DevOps Deploy 8.0 ...
CVE-2024-48944MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. Through a kylin server, an attacker may forge a reques...
CVE-2024-9773HIGH8An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from...
CVE-2024-45361MEDIUM6.5A protocol flaw vulnerability exists in the Xiaomi Mi Connect Service APP. The vulnerability is caused by the validation...
CVE-2024-45356HIGH7.3A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...
CVE-2024-45355MEDIUM5.5A unauthorized access vulnerability exists in the Xiaomi phone framework. The vulnerability is caused by improper valida...
CVE-2024-45354MEDIUM4.3A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper inp...
CVE-2024-45353MEDIUM4.3An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca...
CVE-2024-45352HIGH8.8An code execution vulnerability exists in the Xiaomi smarthome application product. The vulnerability is caused by impro...
CVE-2024-55965MEDIUM6.5An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in...
CVE-2024-55964CRITICAL9.8An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image lea...
CVE-2024-55963MEDIUM6.5An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ...
CVE-2024-41643MEDIUM6.8An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now