2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3684 | HIGH | 7.2 | 1.1% | Apr 19, 2024 | A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an ... |
| CVE-2024-3646 | HIGH | 7.2 | 1.7% | Apr 19, 2024 | A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol... |
| CVE-2024-3470 | HIGH | 7.2 | 0.6% | Apr 19, 2024 | An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us... |
| CVE-2024-32644 | CRITICAL | 9.1 | 0.9% | Apr 19, 2024 | Evmos is a scalable, high-throughput Proof-of-Stake EVM blockchain that is fully compatible and interoperable with Ether... |
| CVE-2024-32478 | MEDIUM | 6.9 | 0.2% | Apr 19, 2024 | Git Credential Manager (GCM) is a secure Git credential helper. Prior to 2.5.0, the Debian package does not set root own... |
| CVE-2024-32038 | CRITICAL | 9.8 | 1.0% | Apr 19, 2024 | Wazuh is a free and open source platform used for threat prevention, detection, and response. There is a buffer overflow... |
| CVE-2024-29030 | MEDIUM | 5.3 | 1.1% | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /api/res... |
| CVE-2024-29028 | MEDIUM | 5.3 | 1.0% | Apr 19, 2024 | memos is a privacy-first, lightweight note-taking service. In memos 0.13.2, an SSRF vulnerability exists at the /o/get/h... |
| CVE-2024-32166 | HIGH | 8.8 | 0.7% | Apr 19, 2024 | Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control vulnerability, allowing att... |
| CVE-2024-3654 | MEDIUM | 6.3 | 0.3% | Apr 19, 2024 | An XSS vulnerability has been found in Teimas Global's Teixo, version 1.42.42-stable. This vulnerability could allow an ... |
| CVE-2024-31745 | — | — | — | Apr 19, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-2002. Reason: This candidate is a duplicate of C... |
| CVE-2024-31744 | HIGH | 7.5 | 0.7% | Apr 19, 2024 | In Jasper 4.2.2, the jpc_streamlist_remove function in src/libjasper/jpc/jpc_dec.c:2407 has an assertion failure vulnera... |
| CVE-2024-32683 | HIGH | 7.5 | 0.5% | Apr 19, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimat... |
| CVE-2024-1065 | MEDIUM | 5.9 | 0.2% | Apr 19, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2024-0671 | MEDIUM | 6.8 | 0.2% | Apr 19, 2024 | Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GP... |
| CVE-2024-29969 | HIGH | 7.5 | 0.3% | Apr 19, 2024 | When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message ... |
| CVE-2024-29968 | MEDIUM | 6.5 | 0.5% | Apr 19, 2024 | An information disclosure vulnerability exists in Brocade SANnav before v2.3.1 and v2.3.0a when Brocade SANnav instances... |
| CVE-2024-2761 | MEDIUM | 6.8 | 0.7% | Apr 19, 2024 | The Genesis Blocks WordPress plugin before 3.1.3 does not properly escape data input provided to some of its blocks, all... |
| CVE-2024-29967 | MEDIUM | 6 | 0.2% | Apr 19, 2024 | In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance ha... |
| CVE-2024-29966 | CRITICAL | 9.8 | 0.7% | Apr 19, 2024 | Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appl... |
| CVE-2024-29965 | MEDIUM | 5.9 | 0.4% | Apr 19, 2024 | In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the com... |
| CVE-2024-29964 | MEDIUM | 6.5 | 0.5% | Apr 19, 2024 | Brocade SANnav versions before v2.3.0a do not correctly set permissions on files, including docker files. An unprivilege... |
| CVE-2024-29962 | MEDIUM | 5.5 | 0.2% | Apr 19, 2024 | Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. T... |
| CVE-2024-29963 | LOW | 3.8 | 0.2% | Apr 19, 2024 | Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded TLS keys used by Docker. Note: Brocade SANnav doesn't ... |
| CVE-2024-29961 | HIGH | 8.2 | 0.8% | Apr 19, 2024 | A vulnerability affects Brocade SANnav before v2.3.1 and v2.3.0a. It allows a Brocade SANnav service to send ping comman... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now