2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39323HIGH7.1aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions ...
CVE-2024-39316MEDIUM6.5Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression De...
CVE-2024-26314HIGH7.8Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and ...
CVE-2024-25088HIGH7.8Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute...
CVE-2024-25087MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue sc...
CVE-2024-25086HIGH7.8Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute...
CVE-2024-22106HIGH7.8Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute ar...
CVE-2024-22105MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue sc...
CVE-2024-4897HIGH8.4parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on ll...
CVE-2024-32932MEDIUM6.8Under certain circumstances the web interface users credentials may be recovered by an authenticated user.
CVE-2024-22104MEDIUM5.5Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen...
CVE-2024-22103MEDIUM5.5Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen...
CVE-2024-22102MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue sc...
CVE-2024-39143MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea...
CVE-2024-38519HIGH7.8`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-d...
CVE-2024-36404CRITICAL9.8GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6,...
CVE-2024-34122HIGH7.8Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a c...
CVE-2024-32757MEDIUM6.8Under certain circumstances unnecessary user details are provided within system logs
CVE-2024-32756MEDIUM6.8Under certain circumstances the Linux users credentials may be recovered by an authenticated user.
CVE-2024-32755CRITICAL9.1Under certain circumstances the web interface will accept characters unrelated to the expected input.
CVE-2024-39119MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=cl...
CVE-2024-6441MEDIUM6.3A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an un...
CVE-2024-6440CRITICAL9.8A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as crit...
CVE-2024-6439CRITICAL9.8A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. Thi...
CVE-2024-6438MEDIUM6.5A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now