2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38372LOW2Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch(...
CVE-2024-6580MEDIUM6.5The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path re...
CVE-2024-6227HIGH7.5A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tr...
CVE-2024-6409HIGH7A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacke...
CVE-2024-4882MEDIUM5.3The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
CVE-2024-39896MEDIUM5.3Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combin...
CVE-2024-1305CRITICAL9.8tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which ...
CVE-2024-39895MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by fie...
CVE-2024-39701HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly...
CVE-2024-39312MEDIUM5.3Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o...
CVE-2024-34702MEDIUM5.3Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier o...
CVE-2024-6564MEDIUM6.7Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter befor...
CVE-2024-6563MEDIUM6.7Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware all...
CVE-2024-39699MEDIUM5Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulne...
CVE-2024-39695MEDIUM6.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2024-39203MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers t...
CVE-2024-39202HIGH8.8D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd...
CVE-2024-31504HIGH7.5Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause ...
CVE-2024-23562HIGH7.5A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthen...
CVE-2024-21778HIGH7.2A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realte...
CVE-2024-39677CRITICAL9.8NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types imp...
CVE-2024-39308MEDIUM5.4RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerabilit...
CVE-2024-25639HIGH7.5Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize...
CVE-2024-4341MEDIUM6.5Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows ...
CVE-2024-39743HIGH7.5IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now