2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21870 | MEDIUM | 4.9 | 0.7% | Apr 3, 2024 | A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Pla... |
| CVE-2024-0394 | HIGH | 7.8 | 0.2% | Apr 3, 2024 | Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated atta... |
| CVE-2024-3258 | HIGH | 7.2 | 0.7% | Apr 3, 2024 | A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been classified as critical.... |
| CVE-2024-3257 | HIGH | 7.2 | 0.7% | Apr 3, 2024 | A vulnerability was found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected... |
| CVE-2024-3256 | HIGH | 7.2 | 0.7% | Apr 3, 2024 | A vulnerability has been found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Aff... |
| CVE-2024-30572 | HIGH | 8 | 1.5% | Apr 3, 2024 | Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter. |
| CVE-2024-30571 | HIGH | 7.5 | 13.8% | Apr 3, 2024 | An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive inform... |
| CVE-2024-30570 | MEDIUM | 5.3 | 1.2% | Apr 3, 2024 | An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without... |
| CVE-2024-30569 | HIGH | 7.5 | 1.9% | Apr 3, 2024 | An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information wi... |
| CVE-2024-30568 | CRITICAL | 9.8 | 47.2% | Apr 3, 2024 | Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. |
| CVE-2024-27254 | MEDIUM | 6.5 | 0.7% | Apr 3, 2024 | IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to... |
| CVE-2024-25096 | CRITICAL | 9.8 | 0.7% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This i... |
| CVE-2024-25046 | MEDIUM | 6.5 | 0.7% | Apr 3, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by ... |
| CVE-2024-25030 | MEDIUM | 5.5 | 0.2% | Apr 3, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log f... |
| CVE-2024-24707 | CRITICAL | 9.9 | 0.7% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Inject... |
| CVE-2024-22360 | MEDIUM | 6.5 | 0.7% | Apr 3, 2024 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a speci... |
| CVE-2024-3255 | HIGH | 7.2 | 0.8% | Apr 3, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Internship Portal Management System 1.0. ... |
| CVE-2024-3254 | HIGH | 7.2 | 0.7% | Apr 3, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Internship Portal Management System ... |
| CVE-2024-31390 | CRITICAL | 9.9 | 0.9% | Apr 3, 2024 | : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.T... |
| CVE-2024-31380 | CRITICAL | 9.9 | 0.8% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. ... |
| CVE-2024-29477 | HIGH | 8.8 | 0.8% | Apr 3, 2024 | Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjace... |
| CVE-2024-28782 | MEDIUM | 6.5 | 0.4% | Apr 3, 2024 | IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores u... |
| CVE-2024-27972 | CRITICAL | 9.9 | 1.6% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.Thi... |
| CVE-2024-27951 | HIGH | 7.2 | 0.6% | Apr 3, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows U... |
| CVE-2024-27191 | HIGH | 8.5 | 0.8% | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now