2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30924 | MEDIUM | 4.6 | 0.3% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin... |
| CVE-2024-22179 | HIGH | 8.7 | 0.4% | Apr 18, 2024 | The application is vulnerable to an unauthenticated parameter manipulation that allows an attacker to set the credentia... |
| CVE-2024-30923 | CRITICAL | 9.8 | 1.4% | Apr 18, 2024 | SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where ... |
| CVE-2024-30922 | CRITICAL | 9.8 | 1.4% | Apr 18, 2024 | SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code via the where Clause in ... |
| CVE-2024-30921 | MEDIUM | 5.4 | 0.6% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-30920 | HIGH | 7.4 | 1.0% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-30107 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized use... |
| CVE-2024-32477 | HIGH | 7.4 | 0.3% | Apr 18, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. By using ANSI escape sequences and a rac... |
| CVE-2024-32474 | MEDIUM | 6.5 | 0.4% | Apr 18, 2024 | Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to ... |
| CVE-2024-20380 | HIGH | 7.5 | 1.1% | Apr 18, 2024 | A vulnerability in the HTML parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of servic... |
| CVE-2024-29987 | MEDIUM | 6.5 | 1.2% | Apr 18, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-29986 | MEDIUM | 5.4 | 0.5% | Apr 18, 2024 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-23557 | MEDIUM | 4.3 | 0.3% | Apr 18, 2024 | HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the u... |
| CVE-2024-32462 | HIGH | 8.4 | 0.5% | Apr 18, 2024 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before ... |
| CVE-2024-24910 | HIGH | 7.3 | 0.2% | Apr 18, 2024 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for ... |
| CVE-2024-32335 | MEDIUM | 5.4 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under ... |
| CVE-2024-32334 | MEDIUM | 6.5 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering und... |
| CVE-2024-32333 | MEDIUM | 4.3 | 0.6% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under t... |
| CVE-2024-32332 | MEDIUM | 6.1 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under th... |
| CVE-2024-32327 | MEDIUM | 5.5 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under... |
| CVE-2024-32326 | MEDIUM | 6.8 | 0.6% | Apr 18, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in t... |
| CVE-2024-32325 | LOW | 2.4 | 0.5% | Apr 18, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the ssid parameter in ... |
| CVE-2024-32475 | HIGH | 7.5 | 0.7% | Apr 18, 2024 | Envoy is a cloud-native, open source edge and service proxy. When an upstream TLS cluster is used with `auto_sni` enable... |
| CVE-2024-32470 | MEDIUM | 6.5 | 0.6% | Apr 18, 2024 | Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission ch... |
| CVE-2024-32466 | MEDIUM | 4.3 | 0.4% | Apr 18, 2024 | Tolgee is an open-source localization platform. For the `/v2/projects/translations` and `/v2/projects/{projectId}/transl... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now