2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28557 | CRITICAL | 9.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr... |
| CVE-2024-28556 | CRITICAL | 9.8 | 1.2% | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitr... |
| CVE-2024-24487 | MEDIUM | 6.8 | 0.3% | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service vi... |
| CVE-2024-24486 | CRITICAL | 9.1 | 0.6% | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the... |
| CVE-2024-24485 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information... |
| CVE-2024-31219 | MEDIUM | 4.3 | 0.4% | Apr 15, 2024 | Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site... |
| CVE-2024-2659 | HIGH | 7.2 | 1.1% | Apr 15, 2024 | A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat... |
| CVE-2024-28056 | CRITICAL | 9.8 | 1.7% | Apr 15, 2024 | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify ... |
| CVE-2024-23594 | MEDIUM | 6.4 | 0.2% | Apr 15, 2024 | A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Win... |
| CVE-2024-23593 | MEDIUM | 6.7 | 0.3% | Apr 15, 2024 | A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 ope... |
| CVE-2024-23559 | MEDIUM | 6.1 | 0.3% | Apr 15, 2024 | HCL DevOps Deploy / Launch is generating an obsolete HTTP header. |
| CVE-2024-22014 | HIGH | 8.8 | 0.8% | Apr 15, 2024 | An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated p... |
| CVE-2024-3797 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerab... |
| CVE-2024-31576 | — | — | — | Apr 15, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-3786 | MEDIUM | 6.6 | 0.7% | Apr 15, 2024 | Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Devi... |
| CVE-2024-3785 | MEDIUM | 6.6 | 0.7% | Apr 15, 2024 | Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Devi... |
| CVE-2024-3784 | MEDIUM | 6.6 | 0.7% | Apr 15, 2024 | Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 A... |
| CVE-2024-3783 | MEDIUM | 6.5 | 0.5% | Apr 15, 2024 | The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low... |
| CVE-2024-3782 | HIGH | 8.8 | 0.3% | Apr 15, 2024 | Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated H... |
| CVE-2024-3781 | CRITICAL | 9.1 | 1.2% | Apr 15, 2024 | Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory... |
| CVE-2024-3780 | HIGH | 7.8 | 0.2% | Apr 15, 2024 | A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerabi... |
| CVE-2024-24898 | MEDIUM | 6 | 0.2% | Apr 15, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Le... |
| CVE-2024-24891 | MEDIUM | 6 | 0.2% | Apr 15, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Le... |
| CVE-2024-3802 | — | — | — | Apr 15, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-32129 | MEDIUM | 4.7 | 0.4% | Apr 15, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now