2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7276HIGH7.2A vulnerability has been found in itsourcecode Alton Management System 1.0 and classified as critical. Affected by this ...
CVE-2024-7275HIGH7.2A vulnerability, which was classified as critical, was found in itsourcecode Alton Management System 1.0. Affected is an...
CVE-2024-7274HIGH7.2A vulnerability, which was classified as critical, has been found in itsourcecode Alton Management System 1.0. This issu...
CVE-2024-37281MEDIUM6.5An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a larg...
CVE-2024-7273CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects...
CVE-2024-5901MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widge...
CVE-2024-38983CRITICAL9.8Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial ...
CVE-2024-41945LOW3.1fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions cau...
CVE-2024-41611CRITICAL9.8In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers ...
CVE-2024-41610CRITICAL9.8D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attacker...
CVE-2024-39012CRITICAL9.8ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerabil...
CVE-2024-39011CRITICAL9.8Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Ser...
CVE-2024-39010CRITICAL9.8chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. Th...
CVE-2024-38986CRITICAL9.8Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (Do...
CVE-2024-38984CRITICAL9.8Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of S...
CVE-2024-36572CRITICAL9.8Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the ...
CVE-2024-5250MEDIUM5.3In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations
CVE-2024-5249HIGH7.5In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.
CVE-2024-41443MEDIUM5.5A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial ...
CVE-2024-41440MEDIUM6.2A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (D...
CVE-2024-41439MEDIUM5.5A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Den...
CVE-2024-41438MEDIUM6.2A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a De...
CVE-2024-41437MEDIUM5.5A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a ...
CVE-2024-3930CRITICAL9.8In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.
CVE-2024-41943MEDIUM4.6I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now