2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26246 | LOW | 3.9 | 0.6% | Mar 14, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2024-26163 | MEDIUM | 4.7 | 2.1% | Mar 14, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2024-1853 | MEDIUM | 5.5 | 0.2% | Mar 14, 2024 | Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x8000... |
| CVE-2024-2249 | MEDIUM | 5.4 | 0.3% | Mar 14, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWr... |
| CVE-2024-26503 | CRITICAL | 9.1 | 1.1% | Mar 14, 2024 | Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to ... |
| CVE-2024-26475 | MEDIUM | 5.5 | 0.3% | Mar 14, 2024 | An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of ... |
| CVE-2024-2256 | MEDIUM | 5.4 | 0.4% | Mar 14, 2024 | The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact... |
| CVE-2024-1713 | HIGH | 7.2 | 0.5% | Mar 14, 2024 | A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as t... |
| CVE-2024-0860 | HIGH | 7.5 | 0.5% | Mar 14, 2024 | The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow ... |
| CVE-2024-28425 | HIGH | 7.5 | 0.6% | Mar 14, 2024 | greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/... |
| CVE-2024-28424 | HIGH | 8.8 | 0.7% | Mar 14, 2024 | zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cl... |
| CVE-2024-28423 | CRITICAL | 9.8 | 0.8% | Mar 14, 2024 | Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at ... |
| CVE-2024-27301 | HIGH | 7.3 | 0.3% | Mar 14, 2024 | Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability i... |
| CVE-2024-27266 | HIGH | 8.2 | 0.8% | Mar 14, 2024 | IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML ... |
| CVE-2024-27265 | MEDIUM | 6.5 | 0.2% | Mar 14, 2024 | IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an atta... |
| CVE-2024-24770 | MEDIUM | 5.3 | 0.4% | Mar 14, 2024 | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le... |
| CVE-2024-24562 | MEDIUM | 5.3 | 0.3% | Mar 14, 2024 | vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers ar... |
| CVE-2024-23823 | MEDIUM | 6.5 | 0.3% | Mar 14, 2024 | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le... |
| CVE-2024-22346 | HIGH | 7.8 | 0.2% | Mar 14, 2024 | Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqua... |
| CVE-2024-28181 | HIGH | 8.1 | 0.8% | Mar 14, 2024 | turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoo... |
| CVE-2024-1998 | — | — | — | Mar 14, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1795. Reason: This candidate is a r... |
| CVE-2024-28849 | MEDIUM | 6.5 | 1.0% | Mar 14, 2024 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows... |
| CVE-2024-25139 | CRITICAL | 10 | 0.9% | Mar 14, 2024 | In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads t... |
| CVE-2024-28323 | MEDIUM | 6.5 | 0.4% | Mar 14, 2024 | The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a pot... |
| CVE-2024-25156 | MEDIUM | 6.5 | 0.4% | Mar 14, 2024 | A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-sp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now