2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-38953MEDIUM6.1phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_co...
CVE-2024-24749HIGH7.5GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.2...
CVE-2024-6425CRITICAL9.1Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote a...
CVE-2024-6424HIGH8.2External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated a...
CVE-2024-6387HIGH8.1A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lea...
CVE-2024-4007HIGH8.8Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login t...
CVE-2024-39853MEDIUM6.5adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerabilit...
CVE-2024-39018MEDIUM6.3harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This v...
CVE-2024-39017CRITICAL9.8agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vul...
CVE-2024-39016HIGH8.1che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability...
CVE-2024-39015CRITICAL9.8cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allo...
CVE-2024-39014CRITICAL9.8ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability al...
CVE-2024-39013CRITICAL9.82o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows a...
CVE-2024-39008CRITICAL10robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vuln...
CVE-2024-39003HIGH7.3amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability...
CVE-2024-39002MEDIUM6.3rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerabi...
CVE-2024-39001MEDIUM6.3ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. T...
CVE-2024-39000MEDIUM6.5adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerabili...
CVE-2024-38999CRITICAL10jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This v...
CVE-2024-38998Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-38997MEDIUM6.5adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vu...
CVE-2024-38996CRITICAL9.8ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.merg...
CVE-2024-38994HIGH7.3amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability a...
CVE-2024-38993CRITICAL9.8rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability ...
CVE-2024-38992HIGH8.8airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerabi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now