2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23298 | MEDIUM | 5.5 | 0.5% | Mar 15, 2024 | A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekee... |
| CVE-2024-28848 | HIGH | 8.8 | 7.9% | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository... |
| CVE-2024-28847 | HIGH | 8.8 | 2.4% | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository... |
| CVE-2024-28255 | CRITICAL | 9.8 | 73.3% | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository... |
| CVE-2024-28254 | HIGH | 8.8 | 45.7% | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository... |
| CVE-2024-28253 | HIGH | 8.8 | 12.5% | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository... |
| CVE-2024-28242 | HIGH | 7.5 | 0.5% | Mar 15, 2024 | Discourse is an open source platform for community discussion. In affected versions an attacker can learn that secret ca... |
| CVE-2024-27920 | HIGH | 7.4 | 0.4% | Mar 15, 2024 | projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant s... |
| CVE-2024-27351 | MEDIUM | 5.3 | 1.9% | Mar 15, 2024 | In Django 3.2 before 3.2.25, 4.2 before 4.2.11, and 5.0 before 5.0.3, the django.utils.text.Truncator.words() method (wi... |
| CVE-2024-27100 | MEDIUM | 6.5 | 0.6% | Mar 15, 2024 | Discourse is an open source platform for community discussion. In affected versions the endpoints for suspending users, ... |
| CVE-2024-27085 | MEDIUM | 6.5 | 0.6% | Mar 15, 2024 | Discourse is an open source platform for community discussion. In affected versions users that are allowed to invite oth... |
| CVE-2024-24827 | HIGH | 7.5 | 0.6% | Mar 15, 2024 | Discourse is an open source platform for community discussion. Without a rate limit on the POST /uploads endpoint, it ma... |
| CVE-2024-24748 | MEDIUM | 5.3 | 0.5% | Mar 15, 2024 | Discourse is an open source platform for community discussion. In affected versions an attacker can learn that a secret ... |
| CVE-2024-28854 | HIGH | 7.5 | 1.0% | Mar 15, 2024 | tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-l... |
| CVE-2024-28851 | HIGH | 7.8 | 0.3% | Mar 15, 2024 | The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive Met... |
| CVE-2024-28252 | HIGH | 7.5 | 0.6% | Mar 15, 2024 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. If you have a NetFraming b... |
| CVE-2024-2537 | CRITICAL | 9.8 | 0.3% | Mar 15, 2024 | Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code In... |
| CVE-2024-2193 | MEDIUM | 5.7 | 1.2% | Mar 15, 2024 | A Speculative Race Condition (SRC) vulnerability that impacts modern CPU architectures supporting speculative execution ... |
| CVE-2024-2497 | HIGH | 7.2 | 0.9% | Mar 15, 2024 | A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown proc... |
| CVE-2024-28404 | HIGH | 8 | 0.5% | Mar 15, 2024 | TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering... |
| CVE-2024-28401 | MEDIUM | 5.4 | 0.4% | Mar 15, 2024 | TOTOLINK X2000R before v1.0.0-B20231213.1013 contains a Store Cross-site scripting (XSS) vulnerability in Root Access Co... |
| CVE-2024-28403 | MEDIUM | 5.4 | 0.4% | Mar 15, 2024 | TOTOLINK X2000R before V1.0.0-B20231213.1013 is vulnerable to Cross Site Scripting (XSS) via the VPN Page. |
| CVE-2024-28319 | MEDIUM | 6.2 | 0.2% | Mar 15, 2024 | gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain an out of boundary read vulnerability via gf_dash_setup_... |
| CVE-2024-28318 | HIGH | 7.1 | 0.5% | Mar 15, 2024 | gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string... |
| CVE-2024-25597 | MEDIUM | 6.1 | 0.4% | Mar 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now