2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42473CRITICAL9.8OpenFGA is an authorization/permission engine. OpenFGA v1.5.7 and v1.5.8 are vulnerable to authorization bypass when cal...
CVE-2024-42470CRITICAL9.1openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. S...
CVE-2024-42469CRITICAL9.8openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. P...
CVE-2024-42468HIGH7.5openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. C...
CVE-2024-42467CRITICAL10openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. I...
CVE-2024-42370HIGH8.3Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-pr...
CVE-2024-42367MEDIUM4.8aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to ...
CVE-2024-42167HIGH7.2The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize spec...
CVE-2024-42166HIGH7.2The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special...
CVE-2024-42165MEDIUM5.4Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accoun...
CVE-2024-42164MEDIUM4.3Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to disable two...
CVE-2024-42163HIGH8.1Insufficiently random values for generating password reset token in FIWARE Keyrock <= 8.4 allow attackers to take over t...
CVE-2024-42001CRITICAL9.8An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeate...
CVE-2024-41936HIGH7.5A directory traversal vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software v...
CVE-2024-41890MEDIUM5.3Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ...
CVE-2024-41888MEDIUM5.3Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: ...
CVE-2024-41577CRITICAL9.8An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arb...
CVE-2024-41570CRITICAL9.8An Unauthenticated Server-Side Request Forgery (SSRF) in demon callback handling in Havoc 2 0.7 allows attackers to send...
CVE-2024-41482MEDIUM6.1Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the MathJax component.
CVE-2024-41481MEDIUM6.1Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.
CVE-2024-41476CRITICAL9.8AMTT Hotel Broadband Operation System (HiBOS) V3.0.3.151204 and before is vulnerable to SQL Injection via /manager/card/...
CVE-2024-41332MEDIUM6.5Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 al...
CVE-2024-40488HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability was found in the Kashipara Live Membership System v1.0. This could lea...
CVE-2024-40487HIGH7.6A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0...
CVE-2024-40486CRITICAL9.8A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execut...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now