2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-39688 | MEDIUM | 6.5 | 0.5% | Jul 22, 2024 | Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated wi... |
| CVE-2024-39686 | CRITICAL | 9.8 | 1.2% | Jul 22, 2024 | Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i... |
| CVE-2024-39685 | CRITICAL | 9.8 | 1.1% | Jul 22, 2024 | Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly i... |
| CVE-2024-41829 | HIGH | 7.5 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection |
| CVE-2024-41828 | MEDIUM | 6.5 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time |
| CVE-2024-41827 | CRITICAL | 9.8 | 0.4% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration |
| CVE-2024-41826 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page |
| CVE-2024-41825 | MEDIUM | 5.4 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab |
| CVE-2024-41824 | MEDIUM | 6.5 | 0.3% | Jul 22, 2024 | In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific ca... |
| CVE-2024-41132 | HIGH | 7.5 | 0.8% | Jul 22, 2024 | ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially... |
| CVE-2024-41131 | HIGH | 7.5 | 0.7% | Jul 22, 2024 | ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allo... |
| CVE-2024-41129 | MEDIUM | 4.4 | 0.2% | Jul 22, 2024 | The ops library is a Python framework for developing and testing Kubernetes and machine charms. The issue here is that o... |
| CVE-2024-32484 | HIGH | 8.2 | 24.4% | Jul 22, 2024 | An reflected XSS vulnerability exists in the handling of invalid paths in the Flask server in Ankitects Anki 24.04. A sp... |
| CVE-2024-32152 | MEDIUM | 4.3 | 11.3% | Jul 22, 2024 | A blocklist bypass vulnerability exists in the LaTeX functionality of Ankitects Anki 24.04. A specially crafted maliciou... |
| CVE-2024-29073 | MEDIUM | 6.5 | 10.8% | Jul 22, 2024 | An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe comm... |
| CVE-2024-26020 | HIGH | 8.8 | 14.1% | Jul 22, 2024 | An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted... |
| CVE-2024-21552 | CRITICAL | 9.8 | 0.6% | Jul 22, 2024 | All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attac... |
| CVE-2024-41320 | HIGH | 8.8 | 2.2% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41318 | CRITICAL | 9.8 | 2.4% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41317 | HIGH | 8 | 2.3% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41316 | CRITICAL | 9.8 | 2.5% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41315 | MEDIUM | 6.8 | 2.1% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname paramet... |
| CVE-2024-41314 | MEDIUM | 6.8 | 2.1% | Jul 22, 2024 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the iface paramete... |
| CVE-2024-39902 | MEDIUM | 4.3 | 0.3% | Jul 22, 2024 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to Tuleap Communi... |
| CVE-2024-39601 | HIGH | 7.1 | 0.5% | Jul 22, 2024 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base syste... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now