2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28418 | MEDIUM | 6.5 | 0.4% | Mar 14, 2024 | Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php |
| CVE-2024-28417 | MEDIUM | 6.3 | 0.3% | Mar 14, 2024 | Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php. |
| CVE-2024-28383 | CRITICAL | 9.8 | 0.8% | Mar 14, 2024 | Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 functio... |
| CVE-2024-1623 | HIGH | 7.8 | 0.2% | Mar 14, 2024 | Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could al... |
| CVE-2024-2438 | — | — | — | Mar 14, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-47851. Reason: This candidate is a ... |
| CVE-2024-2437 | — | — | — | Mar 14, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-41728. Reason: This candidate is a ... |
| CVE-2024-28746 | HIGH | 8.1 | 1.3% | Mar 14, 2024 | Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permiss... |
| CVE-2024-27986 | MEDIUM | 5.4 | 0.3% | Mar 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor... |
| CVE-2024-0313 | MEDIUM | 5.5 | 0.2% | Mar 14, 2024 | A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organiza... |
| CVE-2024-0312 | MEDIUM | 5.5 | 0.2% | Mar 14, 2024 | A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password. |
| CVE-2024-0311 | MEDIUM | 5.5 | 0.4% | Mar 14, 2024 | A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code. |
| CVE-2024-28391 | CRITICAL | 9.8 | 0.6% | Mar 14, 2024 | SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote a... |
| CVE-2024-28390 | CRITICAL | 9.8 | 0.6% | Mar 14, 2024 | An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escala... |
| CVE-2024-22398 | MEDIUM | 4.9 | 0.9% | Mar 14, 2024 | An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Securit... |
| CVE-2024-22397 | HIGH | 8.3 | 1.1% | Mar 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows... |
| CVE-2024-22396 | MEDIUM | 5.3 | 1.1% | Mar 14, 2024 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ... |
| CVE-2024-1884 | MEDIUM | 6.5 | 37.9% | Mar 14, 2024 | This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an atta... |
| CVE-2024-1883 | MEDIUM | 6.1 | 61.5% | Mar 14, 2024 | This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit... |
| CVE-2024-1882 | HIGH | 7.2 | 1.4% | Mar 14, 2024 | This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for ... |
| CVE-2024-28388 | CRITICAL | 9.8 | 0.8% | Mar 14, 2024 | SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote atta... |
| CVE-2024-25653 | MEDIUM | 4.3 | 0.4% | Mar 14, 2024 | Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unli... |
| CVE-2024-25652 | HIGH | 8.4 | 0.6% | Mar 14, 2024 | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access... |
| CVE-2024-25651 | MEDIUM | 5.3 | 0.5% | Mar 14, 2024 | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attack... |
| CVE-2024-25649 | MEDIUM | 6.7 | 0.1% | Mar 14, 2024 | In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machin... |
| CVE-2024-1654 | HIGH | 7.2 | 1.3% | Mar 14, 2024 | This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now