2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31967 | CRITICAL | 9.1 | 0.5% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-31966 | MEDIUM | 6.2 | 0.4% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-31965 | MEDIUM | 4.2 | 0.2% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-31964 | HIGH | 7.5 | 0.6% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-31963 | MEDIUM | 6.4 | 0.3% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-29309 | HIGH | 7.7 | 0.7% | May 2, 2024 | An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Ser... |
| CVE-2024-4406 | CRITICAL | 9.6 | 2.2% | May 2, 2024 | Xiaomi Pro 13 GetApps integral-dialog-page Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2024-4405 | CRITICAL | 9.6 | 1.2% | May 2, 2024 | Xiaomi Pro 13 mimarket manual-upgrade Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2024-4029 | MEDIUM | 4.1 | 0.3% | May 2, 2024 | A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management... |
| CVE-2024-3544 | HIGH | 7.5 | 0.4% | May 2, 2024 | Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to t... |
| CVE-2024-4128 | MEDIUM | 4.3 | 0.1% | May 2, 2024 | This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint th... |
| CVE-2024-3543 | HIGH | 7.5 | 0.3% | May 2, 2024 | Use of reversible password encryption algorithm allows attackers to decrypt passwords. Sensitive information can be ea... |
| CVE-2024-34148 | MEDIUM | 6.8 | 0.8% | May 2, 2024 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 ... |
| CVE-2024-34147 | MEDIUM | 4.3 | 0.5% | May 2, 2024 | Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file... |
| CVE-2024-34146 | MEDIUM | 6.5 | 0.5% | May 2, 2024 | Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git re... |
| CVE-2024-34145 | HIGH | 8.8 | 1.0% | May 2, 2024 | A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jen... |
| CVE-2024-34144 | CRITICAL | 9.8 | 48.1% | May 2, 2024 | A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_... |
| CVE-2024-34061 | MEDIUM | 4.3 | 1.3% | May 2, 2024 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se... |
| CVE-2024-33305 | MEDIUM | 6.1 | 0.4% | May 2, 2024 | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter ... |
| CVE-2024-33303 | HIGH | 8.2 | 0.5% | May 2, 2024 | SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users. |
| CVE-2024-33302 | MEDIUM | 5.3 | 0.3% | May 2, 2024 | SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add ... |
| CVE-2024-30251 | HIGH | 7.5 | 1.1% | May 2, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can sen... |
| CVE-2024-23462 | HIGH | 7.5 | 0.2% | May 2, 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of se... |
| CVE-2024-23461 | MEDIUM | 5.5 | 0.1% | May 2, 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade pr... |
| CVE-2024-23459 | CRITICAL | 9.8 | 0.5% | May 2, 2024 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allow... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now