2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2076 | HIGH | 7.5 | 0.9% | Mar 1, 2024 | A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by... |
| CVE-2024-1453 | HIGH | 7.8 | 0.3% | Mar 1, 2024 | In Sante DICOM Viewer Pro versions 14.0.3 and prior, a user must open a malicious DICOM file, which could allow a local... |
| CVE-2024-2075 | MEDIUM | 5.4 | 0.5% | Mar 1, 2024 | A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by th... |
| CVE-2024-2074 | MEDIUM | 6.3 | 0.8% | Mar 1, 2024 | A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown proce... |
| CVE-2024-27298 | CRITICAL | 10 | 1.0% | Mar 1, 2024 | parse-server is a Parse Server for Node.js / Express. This vulnerability allows SQL injection when Parse Server is confi... |
| CVE-2024-2073 | HIGH | 8.8 | 0.7% | Mar 1, 2024 | A vulnerability has been found in SourceCodester Block Inserter for Dynamic Content 1.0 and classified as critical. This... |
| CVE-2024-2072 | MEDIUM | 5.4 | 0.5% | Mar 1, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Flashcard Quiz App 1.0. This affects a... |
| CVE-2024-2071 | MEDIUM | 5.4 | 0.5% | Mar 1, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affect... |
| CVE-2024-27734 | MEDIUM | 6.1 | 0.5% | Mar 1, 2024 | A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted scrip... |
| CVE-2024-27692 | — | — | — | Mar 1, 2024 | Rejected reason: * REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-22939. Reason: This candidate is a d... |
| CVE-2024-27689 | HIGH | 8.8 | 0.3% | Mar 1, 2024 | Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php. |
| CVE-2024-27559 | MEDIUM | 6.3 | 0.2% | Mar 1, 2024 | Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings.... |
| CVE-2024-27558 | MEDIUM | 6.1 | 0.4% | Mar 1, 2024 | Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings. |
| CVE-2024-2070 | MEDIUM | 6.1 | 0.5% | Mar 1, 2024 | A vulnerability classified as problematic was found in SourceCodester FAQ Management System 1.0. Affected by this vulner... |
| CVE-2024-2069 | MEDIUM | 5.3 | 0.5% | Mar 1, 2024 | A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknow... |
| CVE-2024-2068 | MEDIUM | 6.1 | 2.5% | Mar 1, 2024 | A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been rated as problematic. This issue ... |
| CVE-2024-27499 | MEDIUM | 6.5 | 0.5% | Mar 1, 2024 | Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. |
| CVE-2024-27296 | MEDIUM | 5.3 | 0.6% | Mar 1, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Dire... |
| CVE-2024-27295 | HIGH | 8.2 | 0.7% | Mar 1, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Dir... |
| CVE-2024-27140 | MEDIUM | 5.4 | 1.3% | Mar 1, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vu... |
| CVE-2024-27139 | HIGH | 7.5 | 1.3% | Mar 1, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Arch... |
| CVE-2024-27138 | HIGH | 7.5 | 1.2% | Mar 1, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva. Apache Archiva has a setting t... |
| CVE-2024-1624 | CRITICAL | 9.4 | 2.1% | Mar 1, 2024 | An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x th... |
| CVE-2024-2067 | CRITICAL | 9.8 | 0.5% | Mar 1, 2024 | A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulner... |
| CVE-2024-2066 | MEDIUM | 6.1 | 0.4% | Mar 1, 2024 | A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been classified as problematic. This a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now