2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1900 | MEDIUM | 5.5 | 0.2% | Mar 5, 2024 | Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier a... |
| CVE-2024-1898 | MEDIUM | 4.3 | 0.2% | Mar 5, 2024 | Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privilege... |
| CVE-2024-1764 | HIGH | 7.6 | 0.4% | Mar 5, 2024 | Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allow... |
| CVE-2024-2179 | MEDIUM | 4.8 | 0.3% | Mar 5, 2024 | Concrete CMS version 9 before 9.2.7 is vulnerable to Stored XSS via the Name field of a Group type since there is insuff... |
| CVE-2024-25858 | HIGH | 8.4 | 0.2% | Mar 5, 2024 | In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an ... |
| CVE-2024-25616 | LOW | 3.7 | 0.3% | Mar 5, 2024 | Aruba has identified certain configurations of ArubaOS that can lead to partial disclosure of sensitive information in t... |
| CVE-2024-25615 | MEDIUM | 5.3 | 0.5% | Mar 5, 2024 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol ... |
| CVE-2024-25614 | CRITICAL | 9.1 | 0.5% | Mar 5, 2024 | There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerabil... |
| CVE-2024-25613 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-25612 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-25611 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-1356 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-2056 | CRITICAL | 9.8 | 16.7% | Mar 5, 2024 | Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy servi... |
| CVE-2024-2055 | CRITICAL | 9.8 | 0.9% | Mar 5, 2024 | The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the... |
| CVE-2024-23296 | HIGH | 7.8 | 1.4% | Mar 5, 2024 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i... |
| CVE-2024-23256 | LOW | 3.3 | 0.3% | Mar 5, 2024 | A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's lo... |
| CVE-2024-23243 | LOW | 3.3 | 0.6% | Mar 5, 2024 | A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and ... |
| CVE-2024-23225 | HIGH | 7.8 | 1.5% | Mar 5, 2024 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, i... |
| CVE-2024-22255 | HIGH | 7.1 | 2.3% | Mar 5, 2024 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malic... |
| CVE-2024-22254 | HIGH | 8.2 | 0.5% | Mar 5, 2024 | VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may ... |
| CVE-2024-22253 | MEDIUM | 6.7 | 0.6% | Mar 5, 2024 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious acto... |
| CVE-2024-22252 | MEDIUM | 6.7 | 3.5% | Mar 5, 2024 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious acto... |
| CVE-2024-27931 | MEDIUM | 6.5 | 0.5% | Mar 5, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in... |
| CVE-2024-27929 | HIGH | 7.1 | 0.4% | Mar 5, 2024 | ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's Initi... |
| CVE-2024-27565 | CRITICAL | 9.8 | 0.7% | Mar 5, 2024 | A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now