2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28161 | MEDIUM | 5.3 | 0.4% | Mar 6, 2024 | In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation ... |
| CVE-2024-28160 | HIGH | 8.8 | 1.1% | Mar 6, 2024 | Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored ... |
| CVE-2024-28159 | MEDIUM | 4.3 | 0.5% | Mar 6, 2024 | A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with ... |
| CVE-2024-28158 | MEDIUM | 4.3 | 0.3% | Mar 6, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier... |
| CVE-2024-28157 | HIGH | 8 | 1.1% | Mar 6, 2024 | Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-si... |
| CVE-2024-28156 | MEDIUM | 5.4 | 80.2% | Mar 6, 2024 | Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resultin... |
| CVE-2024-28155 | MEDIUM | 4.3 | 0.4% | Mar 6, 2024 | Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attac... |
| CVE-2024-28154 | MEDIUM | 6.5 | 0.7% | Mar 6, 2024 | Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in... |
| CVE-2024-28153 | MEDIUM | 5.4 | 0.7% | Mar 6, 2024 | Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check rep... |
| CVE-2024-28152 | MEDIUM | 6.3 | 0.6% | Mar 6, 2024 | In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discove... |
| CVE-2024-28151 | MEDIUM | 4.3 | 0.9% | Mar 6, 2024 | Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recre... |
| CVE-2024-28150 | MEDIUM | 4.7 | 0.7% | Mar 6, 2024 | Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as p... |
| CVE-2024-28149 | MEDIUM | 6.5 | 0.7% | Mar 6, 2024 | Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers wi... |
| CVE-2024-20346 | MEDIUM | 5.4 | 0.4% | Mar 6, 2024 | A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remo... |
| CVE-2024-20345 | MEDIUM | 6.5 | 2.2% | Mar 6, 2024 | A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote at... |
| CVE-2024-20338 | HIGH | 7.3 | 0.9% | Mar 6, 2024 | A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, l... |
| CVE-2024-20337 | HIGH | 8.2 | 29.9% | Mar 6, 2024 | A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacke... |
| CVE-2024-20336 | MEDIUM | 6.5 | 0.8% | Mar 6, 2024 | A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allo... |
| CVE-2024-20335 | MEDIUM | 6.5 | 1.0% | Mar 6, 2024 | A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs coul... |
| CVE-2024-20301 | MEDIUM | 6.2 | 0.3% | Mar 6, 2024 | A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to... |
| CVE-2024-20292 | MEDIUM | 5.5 | 0.1% | Mar 6, 2024 | A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authentica... |
| CVE-2024-2005 | HIGH | 8 | 0.5% | Mar 6, 2024 | In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation.... |
| CVE-2024-26580 | CRITICAL | 9.1 | 1.2% | Mar 6, 2024 | Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.... |
| CVE-2024-25103 | MEDIUM | 6.3 | 0.2% | Mar 6, 2024 | This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with... |
| CVE-2024-25102 | HIGH | 7.8 | 0.1% | Mar 6, 2024 | This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now