2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1223 | MEDIUM | 4.8 | 0.4% | Mar 14, 2024 | This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker... |
| CVE-2024-1222 | CRITICAL | 9.8 | 64.0% | Mar 14, 2024 | This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated... |
| CVE-2024-1221 | LOW | 3.1 | 0.5% | Mar 14, 2024 | This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload... |
| CVE-2024-25650 | MEDIUM | 5.9 | 0.3% | Mar 14, 2024 | Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator... |
| CVE-2024-25228 | HIGH | 8.8 | 25.9% | Mar 14, 2024 | Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerify... |
| CVE-2024-28251 | HIGH | 7.3 | 0.2% | Mar 14, 2024 | Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's da... |
| CVE-2024-2242 | MEDIUM | 6.1 | 1.3% | Mar 13, 2024 | The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter i... |
| CVE-2024-2079 | MEDIUM | 5.4 | 0.3% | Mar 13, 2024 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-27703 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do ti... |
| CVE-2024-28662 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag... |
| CVE-2024-28193 | MEDIUM | 6.5 | 0.6% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to creat... |
| CVE-2024-28192 | MEDIUM | 5.3 | 0.6% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQ... |
| CVE-2024-28175 | MEDIUM | 5.4 | 0.7% | Mar 13, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of... |
| CVE-2024-27102 | HIGH | 8.5 | 0.5% | Mar 13, 2024 | Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions... |
| CVE-2024-27097 | MEDIUM | 5.3 | 0.4% | Mar 13, 2024 | A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This... |
| CVE-2024-25250 | CRITICAL | 9.8 | 0.6% | Mar 13, 2024 | SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code vi... |
| CVE-2024-24105 | HIGH | 7.8 | 0.3% | Mar 13, 2024 | SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary co... |
| CVE-2024-22167 | HIGH | 7.9 | 0.2% | Mar 13, 2024 | A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrar... |
| CVE-2024-24693 | MEDIUM | 5.5 | 0.2% | Mar 13, 2024 | Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authentica... |
| CVE-2024-24692 | MEDIUM | 4.7 | 0.1% | Mar 13, 2024 | Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user ... |
| CVE-2024-28194 | CRITICAL | 9.8 | 0.8% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSO... |
| CVE-2024-0801 | HIGH | 7.5 | 41.8% | Mar 13, 2024 | A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll. |
| CVE-2024-0800 | HIGH | 8.8 | 1.0% | Mar 13, 2024 | A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.... |
| CVE-2024-0799 | CRITICAL | 9.8 | 4.3% | Mar 13, 2024 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui... |
| CVE-2024-2433 | LOW | 2.7 | 0.6% | Mar 13, 2024 | An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only admin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now