2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-39310MEDIUM5.4The Basil recipe theme for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `post_title` paramet...
CVE-2024-39309CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability ...
CVE-2024-37765HIGH8.8Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
CVE-2024-37764MEDIUM5.4MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
CVE-2024-37763MEDIUM5.4MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid s...
CVE-2024-37762CRITICAL9.9MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code executio...
CVE-2024-23737MEDIUM5.4Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows a...
CVE-2024-23736HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to ma...
CVE-2024-5322CRITICAL9.1The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can l...
CVE-2024-39305CRITICAL9.1Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy...
CVE-2024-38368CRITICAL9.3trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older p...
CVE-2024-38367CRITICAL9.6trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab44...
CVE-2024-38366CRITICAL10trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies...
CVE-2024-32230HIGH7.8FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in...
CVE-2024-32229HIGH8.4FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.
CVE-2024-32228MEDIUM6.6FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.
CVE-2024-28200CRITICAL9.8The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in a...
CVE-2024-39249HIGH7.5Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in aut...
CVE-2024-39573HIGH7.5Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules t...
CVE-2024-39303MEDIUM5.4Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when resto...
CVE-2024-39251CRITICAL10An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers...
CVE-2024-39236CRITICAL9.8Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. Thi...
CVE-2024-38513CRITICAL9.8Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a sessio...
CVE-2024-38477HIGH7.5null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server vi...
CVE-2024-38476CRITICAL9.8Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local s...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now