2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38475CRITICAL9.1Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to fi...
CVE-2024-38474CRITICAL9.8Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts i...
CVE-2024-38473HIGH8.1Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be...
CVE-2024-38472HIGH7.5SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and maliciou...
CVE-2024-37298HIGH7.5gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a s...
CVE-2024-37146MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-37145MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-36423MEDIUM6.1Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a ...
CVE-2024-36387MEDIUM5.4Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a cr...
CVE-2024-39879MEDIUM5.3In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings
CVE-2024-39878MEDIUM5.3In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection
CVE-2024-36997HIGH8.1In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin...
CVE-2024-36996MEDIUM5.3In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an a...
CVE-2024-36995LOW3.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36994MEDIUM5.4In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36993MEDIUM5.4In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36992MEDIUM5.4In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36991HIGH7.5In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on t...
CVE-2024-36990MEDIUM6.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an a...
CVE-2024-36989MEDIUM4.3In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a lo...
CVE-2024-36987MEDIUM6.5In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an a...
CVE-2024-36986MEDIUM5.7In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9...
CVE-2024-36985HIGH8.8In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or powe...
CVE-2024-36984HIGH8.8In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially...
CVE-2024-36983HIGH8.8In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now