2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30202 | HIGH | 7.8 | 1.1% | Mar 25, 2024 | In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.... |
| CVE-2024-29650 | CRITICAL | 9.8 | 1.4% | Mar 25, 2024 | An issue in @thi.ng/paths v.5.1.62 and before allows a remote attacker to execute arbitrary code via the mutIn and mutIn... |
| CVE-2024-28183 | MEDIUM | 5.7 | 0.2% | Mar 25, 2024 | ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-o... |
| CVE-2024-25175 | MEDIUM | 6.1 | 0.4% | Mar 25, 2024 | An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack. |
| CVE-2024-2865 | CRITICAL | 9.8 | 0.6% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Qu... |
| CVE-2024-28435 | MEDIUM | 5.4 | 0.4% | Mar 25, 2024 | The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload. |
| CVE-2024-28434 | HIGH | 7.6 | 0.7% | Mar 25, 2024 | The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg fil... |
| CVE-2024-28393 | CRITICAL | 9.8 | 0.7% | Mar 25, 2024 | SQL injection vulnerability in scalapay v.1.2.41 and before allows a remote attacker to escalate privileges via the Scal... |
| CVE-2024-28387 | HIGH | 7.5 | 0.4% | Mar 25, 2024 | An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt compone... |
| CVE-2024-28386 | CRITICAL | 9.8 | 1.5% | Mar 25, 2024 | An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getP... |
| CVE-2024-25002 | HIGH | 8.8 | 1.2% | Mar 25, 2024 | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access t... |
| CVE-2024-2864 | MEDIUM | 6.1 | 0.4% | Mar 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify ... |
| CVE-2024-25964 | HIGH | 7.5 | 0.7% | Mar 25, 2024 | Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated at... |
| CVE-2024-30187 | MEDIUM | 5.3 | 0.5% | Mar 25, 2024 | Anope before 2.0.15 does not prevent resetting the password of a suspended account. |
| CVE-2024-2863 | CRITICAL | 9.8 | 67.0% | Mar 25, 2024 | This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant. |
| CVE-2024-2862 | CRITICAL | 9.8 | 51.3% | Mar 25, 2024 | This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affect... |
| CVE-2024-29216 | MEDIUM | 6.1 | 0.2% | Mar 25, 2024 | Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOC... |
| CVE-2024-24899 | HIGH | 7.2 | 1.7% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ao... |
| CVE-2024-24897 | HIGH | 8.1 | 1.4% | Mar 25, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Co... |
| CVE-2024-24892 | HIGH | 8.1 | 0.9% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Managemen... |
| CVE-2024-24890 | HIGH | 7.8 | 1.1% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ga... |
| CVE-2024-29009 | MEDIUM | 6.1 | 0.2% | Mar 25, 2024 | Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker... |
| CVE-2024-21865 | MEDIUM | 6.5 | 0.4% | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at... |
| CVE-2024-21505 | HIGH | 7.5 | 0.7% | Mar 25, 2024 | Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format a... |
| CVE-2024-1962 | HIGH | 8.8 | 0.5% | Mar 25, 2024 | The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attac... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now