2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1013 | HIGH | 7.8 | 0.3% | Mar 18, 2024 | An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee ... |
| CVE-2024-1606 | MEDIUM | 5.4 | 0.4% | Mar 18, 2024 | Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of gener... |
| CVE-2024-1605 | HIGH | 7.8 | 0.2% | Mar 18, 2024 | BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that g... |
| CVE-2024-1604 | MEDIUM | 6.8 | 0.5% | Mar 18, 2024 | Improper authorization in the report management and creation module of BMC Control-M branches 9.0.20 and 9.0.21 allows l... |
| CVE-2024-28039 | MEDIUM | 5.8 | 0.7% | Mar 18, 2024 | Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a rem... |
| CVE-2024-28128 | MEDIUM | 6.1 | 0.6% | Mar 18, 2024 | Cross-site scripting vulnerability exists in FitNesse releases prior to 20220319, which may allow a remote unauthenticat... |
| CVE-2024-28125 | CRITICAL | 9.8 | 1.0% | Mar 18, 2024 | FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of Fi... |
| CVE-2024-27974 | MEDIUM | 6.3 | 0.2% | Mar 18, 2024 | Cross-site request forgery vulnerability in FUJIFILM printers which implement CentreWare Internet Services or Internet S... |
| CVE-2024-23604 | MEDIUM | 6.1 | 0.6% | Mar 18, 2024 | Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to... |
| CVE-2024-22475 | MEDIUM | 6.1 | 0.3% | Mar 18, 2024 | Cross-site request forgery vulnerability in multiple printers and scanners which implement Web Based Management provided... |
| CVE-2024-21824 | MEDIUM | 5.3 | 0.3% | Mar 18, 2024 | Improper authentication vulnerability in exists in multiple printers and scanners which implement Web Based Management p... |
| CVE-2024-29156 | MEDIUM | 6.5 | 0.7% | Mar 18, 2024 | In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL ... |
| CVE-2024-29154 | HIGH | 7.4 | 0.4% | Mar 18, 2024 | danielmiessler fabric through 1.3.0 allows installer/client/gui/static/js/index.js XSS because of innerHTML mishandling,... |
| CVE-2024-29151 | CRITICAL | 9.1 | 0.3% | Mar 18, 2024 | Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI. |
| CVE-2024-28745 | LOW | 3.3 | 0.2% | Mar 18, 2024 | Improper export of Android application components issue exists in 'ABEMA' App for Android prior to 10.65.0 allowing anot... |
| CVE-2024-27757 | MEDIUM | 6.1 | 0.4% | Mar 18, 2024 | flusity CMS through 2.45 allows tools/addons_model.php Gallery Name XSS. The reporter indicates that this product "cease... |
| CVE-2024-2581 | HIGH | 8.8 | 1.3% | Mar 18, 2024 | A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function fromSetR... |
| CVE-2024-2577 | CRITICAL | 9.8 | 0.7% | Mar 18, 2024 | A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vu... |
| CVE-2024-24539 | MEDIUM | 5.3 | 0.5% | Mar 18, 2024 | FusionPBX before 5.2.0 does not validate a session. |
| CVE-2024-2576 | CRITICAL | 9.8 | 0.7% | Mar 18, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This... |
| CVE-2024-2575 | CRITICAL | 9.8 | 0.7% | Mar 18, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0.... |
| CVE-2024-2574 | CRITICAL | 9.8 | 0.7% | Mar 18, 2024 | A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this... |
| CVE-2024-24230 | HIGH | 7.5 | 0.7% | Mar 18, 2024 | Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It al... |
| CVE-2024-2573 | CRITICAL | 9.8 | 1.0% | Mar 18, 2024 | A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is... |
| CVE-2024-2572 | CRITICAL | 9.8 | 1.0% | Mar 18, 2024 | A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This iss... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now