2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3515 | MEDIUM | 6.5 | 0.8% | Apr 10, 2024 | Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-3157 | CRITICAL | 9.6 | 0.8% | Apr 10, 2024 | Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had co... |
| CVE-2024-31464 | MEDIUM | 4.9 | 0.4% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9... |
| CVE-2024-31386 | MEDIUM | 4.3 | 0.4% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Defaul... |
| CVE-2024-28345 | MEDIUM | 5.5 | 0.4% | Apr 10, 2024 | An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpo... |
| CVE-2024-28344 | LOW | 3.1 | 0.5% | Apr 10, 2024 | An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability al... |
| CVE-2024-23077 | HIGH | 7.5 | 0.6% | Apr 10, 2024 | JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.jav... |
| CVE-2024-31944 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This... |
| CVE-2024-31943 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affect... |
| CVE-2024-31461 | CRITICAL | 9.1 | 0.7% | Apr 10, 2024 | Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior ... |
| CVE-2024-31242 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. |
| CVE-2024-31230 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affec... |
| CVE-2024-31214 | CRITICAL | 9.6 | 17.6% | Apr 10, 2024 | Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded th... |
| CVE-2024-3570 | MEDIUM | 5.4 | 0.3% | Apr 10, 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm rep... |
| CVE-2024-3569 | HIGH | 7.5 | 0.8% | Apr 10, 2024 | A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is runn... |
| CVE-2024-3568 | CRITICAL | 9.6 | 2.1% | Apr 10, 2024 | The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data... |
| CVE-2024-3388 | MEDIUM | 5 | 0.3% | Apr 10, 2024 | A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to ... |
| CVE-2024-3387 | MEDIUM | 5.9 | 0.2% | Apr 10, 2024 | A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a me... |
| CVE-2024-3386 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclus... |
| CVE-2024-3385 | HIGH | 7.5 | 0.9% | Apr 10, 2024 | A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based f... |
| CVE-2024-3384 | HIGH | 7.5 | 0.9% | Apr 10, 2024 | A vulnerability in Palo Alto Networks PAN-OS software enables a remote attacker to reboot PAN-OS firewalls when receivin... |
| CVE-2024-3383 | CRITICAL | 9.1 | 0.6% | Apr 10, 2024 | A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agent... |
| CVE-2024-3382 | HIGH | 7.5 | 0.9% | Apr 10, 2024 | A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets t... |
| CVE-2024-3283 | HIGH | 7.2 | 0.9% | Apr 10, 2024 | A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin role... |
| CVE-2024-3101 | HIGH | 7.2 | 0.8% | Apr 10, 2024 | In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by dea... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now