2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29387 | HIGH | 8.8 | 1.2% | Apr 4, 2024 | projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/pri... |
| CVE-2024-29386 | MEDIUM | 5.4 | 0.4% | Apr 4, 2024 | projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceE... |
| CVE-2024-27316 | HIGH | 7.5 | 91.3% | Apr 4, 2024 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP... |
| CVE-2024-24795 | MEDIUM | 6.3 | 2.9% | Apr 4, 2024 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response ... |
| CVE-2024-22053 | HIGH | 8.2 | 3.5% | Apr 4, 2024 | A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an... |
| CVE-2024-22052 | HIGH | 7.5 | 3.8% | Apr 4, 2024 | A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secur... |
| CVE-2024-22023 | MEDIUM | 5.3 | 3.0% | Apr 4, 2024 | An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Se... |
| CVE-2024-30254 | MEDIUM | 5.8 | 0.2% | Apr 4, 2024 | MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1... |
| CVE-2024-30252 | LOW | 2.6 | 0.3% | Apr 4, 2024 | Livemarks is a browser extension that provides RSS feed bookmark folders. Versions of Livemarks prior to 3.7 are vulnera... |
| CVE-2024-30249 | HIGH | 8.6 | 0.6% | Apr 4, 2024 | Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.... |
| CVE-2024-29193 | MEDIUM | 6.1 | 0.5% | Apr 4, 2024 | gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th... |
| CVE-2024-25007 | HIGH | 7.1 | 0.4% | Apr 4, 2024 | Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application ... |
| CVE-2024-2660 | MEDIUM | 6.8 | 0.3% | Apr 4, 2024 | Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP ... |
| CVE-2024-29192 | HIGH | 8.8 | 0.5% | Apr 4, 2024 | gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/... |
| CVE-2024-28787 | CRITICAL | 10 | 0.8% | Apr 4, 2024 | IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote at... |
| CVE-2024-27268 | HIGH | 7.5 | 1.3% | Apr 4, 2024 | IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sendi... |
| CVE-2024-25709 | MEDIUM | 6.1 | 0.5% | Apr 4, 2024 | There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may al... |
| CVE-2024-25708 | MEDIUM | 4.8 | 0.4% | Apr 4, 2024 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.... |
| CVE-2024-25706 | MEDIUM | 6.1 | 0.4% | Apr 4, 2024 | There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticat... |
| CVE-2024-25705 | MEDIUM | 5.4 | 0.5% | Apr 4, 2024 | There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below... |
| CVE-2024-25704 | — | — | — | Apr 4, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is schedul... |
| CVE-2024-25703 | — | — | — | Apr 4, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because this item is schedul... |
| CVE-2024-25700 | MEDIUM | 4.8 | 0.4% | Apr 4, 2024 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 ... |
| CVE-2024-25699 | HIGH | 8.5 | 0.7% | Apr 4, 2024 | There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS version... |
| CVE-2024-25698 | MEDIUM | 6.1 | 0.4% | Apr 4, 2024 | There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now