2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20670 | HIGH | 8.1 | 2.3% | Apr 9, 2024 | Outlook for Windows Spoofing Vulnerability |
| CVE-2024-20669 | MEDIUM | 6.7 | 0.6% | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2024-20665 | MEDIUM | 6.7 | 0.7% | Apr 9, 2024 | BitLocker Security Feature Bypass Vulnerability |
| CVE-2024-3281 | HIGH | 8.8 | 0.5% | Apr 9, 2024 | A vulnerability was discovered in the firmware builds after 8.0.2.3267 and prior to 8.1.3.1301 in CCX devices. A flaw in... |
| CVE-2024-31868 | MEDIUM | 6.1 | 1.3% | Apr 9, 2024 | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and expo... |
| CVE-2024-31866 | CRITICAL | 9.8 | 1.4% | Apr 9, 2024 | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or ma... |
| CVE-2024-31865 | MEDIUM | 6.5 | 1.7% | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im... |
| CVE-2024-31864 | CRITICAL | 9.8 | 1.3% | Apr 9, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sen... |
| CVE-2024-28235 | MEDIUM | 6.5 | 0.7% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, w... |
| CVE-2024-31487 | MEDIUM | 6.5 | 0.9% | Apr 9, 2024 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2024-23671 | HIGH | 8.1 | 1.2% | Apr 9, 2024 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2024-23662 | HIGH | 7.5 | 0.7% | Apr 9, 2024 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 throug... |
| CVE-2024-21756 | HIGH | 8.8 | 2.2% | Apr 9, 2024 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2024-21755 | HIGH | 8.8 | 2.5% | Apr 9, 2024 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2024-28234 | MEDIUM | 4.7 | 0.6% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, i... |
| CVE-2024-28191 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it... |
| CVE-2024-28190 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, us... |
| CVE-2024-31544 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to exec... |
| CVE-2024-2224 | CRITICAL | 9.8 | 0.7% | Apr 9, 2024 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer compone... |
| CVE-2024-2223 | CRITICAL | 9.8 | 0.5% | Apr 9, 2024 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Ser... |
| CVE-2024-31863 | MEDIUM | 5.3 | 1.0% | Apr 9, 2024 | Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apa... |
| CVE-2024-3046 | HIGH | 7.5 | 0.6% | Apr 9, 2024 | In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet ... |
| CVE-2024-31862 | MEDIUM | 5.3 | 1.4% | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affect... |
| CVE-2024-31978 | HIGH | 7.6 | 0.5% | Apr 9, 2024 | A vulnerability has been identified in SINEC NMS (All versions < V2.0 SP2). Affected devices allow authenticated users t... |
| CVE-2024-31860 | MEDIUM | 6.5 | 1.4% | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can s... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now