2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1224 | HIGH | 7.1 | 0.1% | Mar 6, 2024 | This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user logi... |
| CVE-2024-2211 | MEDIUM | 6.1 | 0.3% | Mar 6, 2024 | Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacke... |
| CVE-2024-26628 | — | — | — | Mar 6, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-26627 | MEDIUM | 5.5 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock ... |
| CVE-2024-26626 | MEDIUM | 5.5 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packet... |
| CVE-2024-26625 | HIGH | 7.8 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot rep... |
| CVE-2024-26624 | — | — | — | Mar 6, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-26623 | MEDIUM | 4.7 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq ... |
| CVE-2024-1989 | MEDIUM | 5.4 | 0.5% | Mar 6, 2024 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-1771 | MEDIUM | 4.3 | 0.4% | Mar 6, 2024 | The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th... |
| CVE-2024-1760 | MEDIUM | 4.7 | 0.3% | Mar 6, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cro... |
| CVE-2024-1220 | HIGH | 7.5 | 0.7% | Mar 6, 2024 | A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and pri... |
| CVE-2024-27278 | MEDIUM | 5.4 | 0.3% | Mar 6, 2024 | OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which us... |
| CVE-2024-25817 | HIGH | 7.8 | 0.3% | Mar 6, 2024 | Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .gi... |
| CVE-2024-22889 | HIGH | 7.5 | 0.7% | Mar 6, 2024 | Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the webs... |
| CVE-2024-27765 | HIGH | 7.5 | 0.9% | Mar 5, 2024 | Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information vi... |
| CVE-2024-27764 | CRITICAL | 9.8 | 1.0% | Mar 5, 2024 | An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component. |
| CVE-2024-24786 | HIGH | 7.5 | 1.3% | Mar 5, 2024 | The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condit... |
| CVE-2024-24785 | MEDIUM | 5.4 | 0.8% | Mar 5, 2024 | If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-... |
| CVE-2024-24784 | HIGH | 7.5 | 1.0% | Mar 5, 2024 | The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is... |
| CVE-2024-24783 | MEDIUM | 5.9 | 0.7% | Mar 5, 2024 | Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.V... |
| CVE-2024-24278 | HIGH | 7.5 | 0.7% | Mar 5, 2024 | An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive informa... |
| CVE-2024-24276 | CRITICAL | 9.6 | 0.9% | Mar 5, 2024 | Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote atta... |
| CVE-2024-24275 | CRITICAL | 9.6 | 0.9% | Mar 5, 2024 | Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker t... |
| CVE-2024-1901 | MEDIUM | 4.3 | 0.3% | Mar 5, 2024 | Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authe... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now