2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39688MEDIUM6.5Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated wi...
CVE-2024-39686CRITICAL9.8Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i...
CVE-2024-39685CRITICAL9.8Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i...
CVE-2024-41829HIGH7.5In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
CVE-2024-41828MEDIUM6.5In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
CVE-2024-41827CRITICAL9.8In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
CVE-2024-41826MEDIUM4.8In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
CVE-2024-41825MEDIUM5.4In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
CVE-2024-41824MEDIUM6.5In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific ca...
CVE-2024-41132HIGH7.5ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially...
CVE-2024-41131HIGH7.5ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allo...
CVE-2024-41129MEDIUM4.4The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that o...
CVE-2024-32484HIGH8.2An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A sp...
CVE-2024-32152MEDIUM4.3A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted maliciou...
CVE-2024-29073MEDIUM6.5An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe comm...
CVE-2024-26020HIGH8.8An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted...
CVE-2024-21552CRITICAL9.8All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attac...
CVE-2024-41320HIGH8.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41318CRITICAL9.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41317HIGH8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41316CRITICAL9.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41315MEDIUM6.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet...
CVE-2024-41314MEDIUM6.8TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface paramete...
CVE-2024-39902MEDIUM4.3Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Communi...
CVE-2024-39601HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now