Skip to main content

Year archive

CVEs published in 2024

Archive summary

39,957 CVEs published in 2024 — 3,705 Critical, 13,537 High, 21,359 Medium, 1,341 Low, 15 Unrated.

CVE-2023-5879

Published Jan 3, 2024

Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices.…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50090

Published Jan 3, 2024

Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46929

Published Jan 3, 2024

An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui /afltest/gpac/src/media_tools/av_parsers.c:6872:55 allows attackers to crash the applic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21633

Published Jan 3, 2024

Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-21631

Published Jan 3, 2024

Vapor is an HTTP web framework for Swift. Prior to version 4.90.0, Vapor's `vapor_urlparser_parse` function uses `uint16_t` indexes when parsing a URI's components, which may caus…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21622

Published Jan 3, 2024

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50253

Published Jan 3, 2024

Laf is a cloud development platform. In the Laf version design, the log uses communication with k8s to quickly retrieve logs from the container without the need for additional sto…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46742

Published Jan 3, 2024

CubeFS is an open-source cloud-native file storage system. CubeFS prior to version 3.3.1 was found to leak users secret keys and access keys in the logs in multiple components. Wh…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46741

Published Jan 3, 2024

CubeFS is an open-source cloud-native file storage system. A vulnerability was found in CubeFS prior to version 3.3.1 that could allow users to read sensitive data from the logs w…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46740

Published Jan 3, 2024

CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46739

Published Jan 3, 2024

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could allow an untrusted…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21911

Published Jan 3, 2024

TinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulti…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
34.4
Vendor/product tagsBeta · best-effort

CVE-2024-21910

Published Jan 3, 2024

TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would re…

CVSS 6.1 · Medium
evidence mentions
6
Buzz score
34.5
Vendor/product tagsBeta · best-effort

CVE-2024-21909

Published Jan 3, 2024

PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data t…

CVSS 7.5 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2024-21908

Published Jan 3, 2024

TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulti…

CVSS 6.1 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2024-21907

Published Jan 3, 2024

Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method…

CVSS 7.5 · High
evidence mentions
10
Buzz score
48.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-46738

Published Jan 3, 2024

CubeFS is an open-source cloud-native file storage system. A security vulnerability was found in CubeFS HandlerNode in versions prior to 3.3.1 that could allow authenticated users…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30617

Published Jan 3, 2024

Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has gained…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45559

Published Jan 3, 2024

An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 39,751-39,775 of 39,957 CVEsPage 1591 of 1599