2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53351CRITICAL9.8Insecure permissions in pipecd v0.49 allow attackers to gain access to the service account's token, leading to escalatio...
CVE-2024-53350HIGH7.4Insecure permissions in kubeslice v1.3.1 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53349HIGH7.4Insecure permissions in kuadrant v0.11.3 allow attackers to gain access to the service account's token, leading to escal...
CVE-2024-53348HIGH7.4LoxiLB v.0.9.7 and before is vulnerable to Incorrect Access Control which allows attackers to obtain sensitive informati...
CVE-2024-57490HIGH7.7Guangzhou Hongfan Technology Co., LTD. iOffice20 has any user login vulnerability. An attacker can log in to any system ...
CVE-2024-13903HIGH7.5A vulnerability was found in quickjs-ng QuickJS up to 0.8.0. It has been declared as problematic. Affected by this vulne...
CVE-2024-50053MEDIUM5.4Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below...
CVE-2024-54564MEDIUM6.5This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom...
CVE-2024-54551HIGH7.5The issue was addressed with improved memory handling. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, mac...
CVE-2024-44305HIGH7.8This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14.6. An app may be able t...
CVE-2024-44199HIGH7.1An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.6. An app may...
CVE-2024-7598LOW3.1A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enf...
CVE-2024-57440HIGH7.5D-Link DSL-3788 revA1 1.01R1B036_EU_EN is vulnerable to Buffer Overflow via the COMM_MAKECustomMsg function of the webpr...
CVE-2024-48591MEDIUM6.1Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded tha...
CVE-2024-48590CRITICAL9.8Inflectra SpiraTeam 7.2.00 is vulnerable to Server-Side Request Forgery (SSRF) via the NewsReaderService. This allows an...
CVE-2024-13923MEDIUM6.5The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
CVE-2024-13922MEDIUM6.5The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins...
CVE-2024-13921HIGH7.2The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versio...
CVE-2024-13920MEDIUM4.9The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version...
CVE-2024-13558MEDIUM5.3The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi...
CVE-2024-9920HIGH8.8In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, ...
CVE-2024-9919HIGH8.4A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauth...
CVE-2024-9901——Rejected reason: ** REJECT ** DO NOT USE THIS CVE ID NUMBER. The Rejected CVE Record is a duplicate of CVE-2024-48057. N...
CVE-2024-9900MEDIUM6.1mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vuln...
CVE-2024-9880——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now