2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27476 | MEDIUM | 4.7 | 0.6% | Apr 10, 2024 | Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket. |
| CVE-2024-27474 | HIGH | 8.8 | 0.7% | Apr 10, 2024 | Leantime 3.0.6 is vulnerable to Cross Site Request Forgery (CSRF). This vulnerability allows malicious actors to perform... |
| CVE-2024-24809 | HIGH | 8.5 | 54.4% | Apr 10, 2024 | Traccar is an open source GPS tracking system. Versions prior to 6.0 are vulnerable to path traversal and unrestricted u... |
| CVE-2024-3448 | MEDIUM | 5 | 0.4% | Apr 10, 2024 | Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?act... |
| CVE-2024-2731 | MEDIUM | 5.4 | 0.4% | Apr 10, 2024 | Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages ... |
| CVE-2024-2730 | MEDIUM | 5.3 | 0.5% | Apr 10, 2024 | Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated use... |
| CVE-2024-26816 | MEDIUM | 5.5 | 0.3% | Apr 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86, relocs: Ignore relocations in .notes section ... |
| CVE-2024-23083 | MEDIUM | 5.3 | 0.8% | Apr 10, 2024 | Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatU... |
| CVE-2024-31924 | MEDIUM | 4.3 | 0.3% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in nosilver4u EWWW Image Optimizer ewww-image-optimizer.This issue affec... |
| CVE-2024-31492 | HIGH | 7.8 | 0.3% | Apr 10, 2024 | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.... |
| CVE-2024-23080 | CRITICAL | 9.1 | 1.0% | Apr 10, 2024 | Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::... |
| CVE-2024-20772 | HIGH | 7.8 | 0.6% | Apr 10, 2024 | Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could... |
| CVE-2024-20770 | MEDIUM | 5.5 | 0.3% | Apr 10, 2024 | Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lea... |
| CVE-2024-20766 | MEDIUM | 5.5 | 0.3% | Apr 10, 2024 | InDesign Desktop versions 18.5.1, 19.2 and earlier are affected by an out-of-bounds read vulnerability that could lead t... |
| CVE-2024-31309 | HIGH | 7.5 | 94.6% | Apr 10, 2024 | HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.... |
| CVE-2024-23076 | HIGH | 7.5 | 1.0% | Apr 10, 2024 | JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /labels/BubbleXYItemLabelGenerator.... |
| CVE-2024-20759 | HIGH | 8.1 | 1.0% | Apr 10, 2024 | Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by a stored Cross-Site Script... |
| CVE-2024-20758 | CRITICAL | 9 | 1.4% | Apr 10, 2024 | Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validati... |
| CVE-2024-2243 | HIGH | 8.8 | 1.1% | Apr 10, 2024 | A vulnerability was found in csmock where a regular user of the OSH service (anyone with a valid Kerberos ticket) can us... |
| CVE-2024-26815 | MEDIUM | 5.5 | 0.3% | Apr 10, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX... |
| CVE-2024-26122 | MEDIUM | 5.4 | 0.5% | Apr 10, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-26098 | MEDIUM | 5.4 | 0.5% | Apr 10, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-26097 | MEDIUM | 5.4 | 0.5% | Apr 10, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-26087 | MEDIUM | 5.4 | 0.5% | Apr 10, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-26084 | MEDIUM | 5.4 | 0.5% | Apr 10, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now