2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29185 | CRITICAL | 9 | 1.7% | Mar 22, 2024 | FreeScout is a self-hosted help desk and shared mailbox. Versions prior to 1.8.128 are vulnerable to OS Command Injectio... |
| CVE-2024-29184 | HIGH | 8 | 0.9% | Mar 22, 2024 | FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been iden... |
| CVE-2024-29042 | MEDIUM | 5.3 | 0.7% | Mar 22, 2024 | Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to ver... |
| CVE-2024-28861 | CRITICAL | 9.8 | 1.5% | Mar 22, 2024 | Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version... |
| CVE-2024-2821 | MEDIUM | 4.3 | 0.4% | Mar 22, 2024 | A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unkn... |
| CVE-2024-2820 | MEDIUM | 4.3 | 0.4% | Mar 22, 2024 | A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functio... |
| CVE-2024-2228 | HIGH | 8.8 | 0.4% | Mar 22, 2024 | This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user... |
| CVE-2024-2227 | HIGH | 7.5 | 0.8% | Mar 22, 2024 | This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulner... |
| CVE-2024-29865 | MEDIUM | 5.4 | 0.3% | Mar 22, 2024 | Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. |
| CVE-2024-28593 | MEDIUM | 5.4 | 0.6% | Mar 22, 2024 | The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTM... |
| CVE-2024-2728 | MEDIUM | 5.5 | 0.2% | Mar 22, 2024 | Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept t... |
| CVE-2024-2727 | MEDIUM | 6.1 | 0.3% | Mar 22, 2024 | HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify ... |
| CVE-2024-2726 | MEDIUM | 6.1 | 0.3% | Mar 22, 2024 | Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and... |
| CVE-2024-2725 | HIGH | 7.5 | 0.6% | Mar 22, 2024 | Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/ins... |
| CVE-2024-2724 | HIGH | 7.5 | 0.7% | Mar 22, 2024 | SQL injection vulnerability in the CIGESv2 system, through /ajaxServiciosAtencion.php, in the 'idServicio' parameter. Th... |
| CVE-2024-2723 | HIGH | 7.5 | 0.7% | Mar 22, 2024 | SQL injection vulnerability in the CIGESv2 system, through /ajaxSubServicios.php, in the 'idServicio' parameter. The exp... |
| CVE-2024-2722 | HIGH | 7.5 | 0.7% | Mar 22, 2024 | SQL injection vulnerability in the CIGESv2 system, through /ajaxConfigTotem.php, in the 'id' parameter. The exploitation... |
| CVE-2024-2449 | HIGH | 7.5 | 12.9% | Mar 22, 2024 | A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who... |
| CVE-2024-2448 | HIGH | 8.8 | 55.4% | Mar 22, 2024 | An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission s... |
| CVE-2024-29944 | HIGH | 8.4 | 4.7% | Mar 22, 2024 | An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution... |
| CVE-2024-29943 | CRITICAL | 9.8 | 22.9% | Mar 22, 2024 | An attacker was able to perform an out-of-bounds read or write on a JavaScript object by fooling range-based bounds chec... |
| CVE-2024-28560 | MEDIUM | 5.4 | 0.5% | Mar 22, 2024 | SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the delete... |
| CVE-2024-28559 | HIGH | 8.8 | 0.8% | Mar 22, 2024 | SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPri... |
| CVE-2024-25168 | MEDIUM | 6.3 | 0.6% | Mar 22, 2024 | SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope pa... |
| CVE-2024-28824 | HIGH | 7.8 | 0.2% | Mar 22, 2024 | Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now