2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29863 | HIGH | 7.8 | 0.4% | Apr 5, 2024 | A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR... |
| CVE-2024-26329 | MEDIUM | 6.2 | 0.3% | Apr 5, 2024 | Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBy... |
| CVE-2024-29672 | HIGH | 8.8 | 1.3% | Apr 5, 2024 | Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code v... |
| CVE-2024-27448 | CRITICAL | 9.1 | 0.9% | Apr 5, 2024 | MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading t... |
| CVE-2024-22363 | HIGH | 7.5 | 0.8% | Apr 5, 2024 | SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS). |
| CVE-2024-2509 | MEDIUM | 6.5 | 0.4% | Apr 5, 2024 | The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block opt... |
| CVE-2024-3321 | MEDIUM | 4.8 | 0.5% | Apr 5, 2024 | A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown... |
| CVE-2024-3320 | MEDIUM | 6.1 | 0.6% | Apr 5, 2024 | A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this iss... |
| CVE-2024-31498 | HIGH | 8.8 | 0.6% | Apr 4, 2024 | Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation b... |
| CVE-2024-31212 | HIGH | 7.2 | 0.9% | Apr 4, 2024 | InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2... |
| CVE-2024-31211 | CRITICAL | 9.8 | 2.7% | Apr 4, 2024 | WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows f... |
| CVE-2024-31210 | HIGH | 8.8 | 0.9% | Apr 4, 2024 | WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be sub... |
| CVE-2024-31206 | HIGH | 8.2 | 0.3% | Apr 4, 2024 | dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to th... |
| CVE-2024-27981 | CRITICAL | 9.8 | 1.2% | Apr 4, 2024 | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V... |
| CVE-2024-21894 | CRITICAL | 9.8 | 19.0% | Apr 4, 2024 | A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an... |
| CVE-2024-3316 | HIGH | 8.8 | 0.6% | Apr 4, 2024 | A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical.... |
| CVE-2024-29981 | MEDIUM | 4.3 | 0.7% | Apr 4, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-29049 | MEDIUM | 4.7 | 0.7% | Apr 4, 2024 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability |
| CVE-2024-3315 | CRITICAL | 9.8 | 0.7% | Apr 4, 2024 | A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critica... |
| CVE-2024-3314 | CRITICAL | 9.8 | 0.5% | Apr 4, 2024 | A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This i... |
| CVE-2024-3311 | HIGH | 8.8 | 1.0% | Apr 4, 2024 | A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability... |
| CVE-2024-31204 | MEDIUM | 6.1 | 8.2% | Apr 4, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie... |
| CVE-2024-30270 | MEDIUM | 6.2 | 27.3% | Apr 4, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie... |
| CVE-2024-30264 | CRITICAL | 9.3 | 0.8% | Apr 4, 2024 | Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prio... |
| CVE-2024-30255 | HIGH | 7.5 | 87.8% | Apr 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now