2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28111 | MEDIUM | 6.5 | 0.6% | Mar 6, 2024 | Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canaryt... |
| CVE-2024-28110 | HIGH | 7.5 | 0.7% | Mar 6, 2024 | Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15... |
| CVE-2024-27917 | HIGH | 7.5 | 0.6% | Mar 6, 2024 | Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session C... |
| CVE-2024-27915 | HIGH | 8.1 | 0.4% | Mar 6, 2024 | Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to page... |
| CVE-2024-27308 | CRITICAL | 9.1 | 0.9% | Mar 6, 2024 | Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid... |
| CVE-2024-27307 | CRITICAL | 9.8 | 1.4% | Mar 6, 2024 | JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a m... |
| CVE-2024-2176 | HIGH | 8.8 | 1.3% | Mar 6, 2024 | Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-2174 | HIGH | 8.8 | 12.6% | Mar 6, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exp... |
| CVE-2024-2173 | HIGH | 8.8 | 13.6% | Mar 6, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of b... |
| CVE-2024-27304 | CRITICAL | 9.8 | 1.1% | Mar 6, 2024 | pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind m... |
| CVE-2024-27303 | HIGH | 7.3 | 0.3% | Mar 6, 2024 | electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Wind... |
| CVE-2024-27302 | CRITICAL | 9.1 | 0.8% | Mar 6, 2024 | go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - whic... |
| CVE-2024-27289 | HIGH | 8.1 | 0.9% | Mar 6, 2024 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the followin... |
| CVE-2024-27288 | LOW | 3.1 | 0.5% | Mar 6, 2024 | 1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can... |
| CVE-2024-27287 | HIGH | 8.7 | 0.7% | Mar 6, 2024 | ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior t... |
| CVE-2024-25111 | HIGH | 7.5 | 65.3% | Mar 6, 2024 | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of ... |
| CVE-2024-24766 | HIGH | 7.5 | 0.8% | Mar 6, 2024 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ... |
| CVE-2024-24767 | CRITICAL | 9.8 | 1.0% | Mar 6, 2024 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ... |
| CVE-2024-24765 | CRITICAL | 9.8 | 1.0% | Mar 6, 2024 | CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL... |
| CVE-2024-24761 | HIGH | 7.5 | 0.6% | Mar 6, 2024 | Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to ... |
| CVE-2024-2216 | HIGH | 8.8 | 0.8% | Mar 6, 2024 | A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers wit... |
| CVE-2024-2215 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers ... |
| CVE-2024-28174 | MEDIUM | 5.8 | 0.3% | Mar 6, 2024 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized i... |
| CVE-2024-28173 | MEDIUM | 4.3 | 0.5% | Mar 6, 2024 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed |
| CVE-2024-28162 | MEDIUM | 4.2 | 0.3% | Mar 6, 2024 | In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable S... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now