2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27284 | HIGH | 7.5 | 0.8% | Feb 29, 2024 | cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterat... |
| CVE-2024-27092 | MEDIUM | 5.4 | 0.6% | Feb 29, 2024 | Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad... |
| CVE-2024-27083 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerabil... |
| CVE-2024-26473 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious J... |
| CVE-2024-26472 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may ... |
| CVE-2024-26471 | MEDIUM | 5.4 | 0.5% | Feb 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaS... |
| CVE-2024-26470 | HIGH | 8.1 | 1.0% | Feb 29, 2024 | A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v... |
| CVE-2024-26462 | MEDIUM | 5.5 | 0.4% | Feb 29, 2024 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. |
| CVE-2024-26461 | HIGH | 7.5 | 1.1% | Feb 29, 2024 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| CVE-2024-26458 | MEDIUM | 5.3 | 0.8% | Feb 29, 2024 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. |
| CVE-2024-26132 | LOW | 3.3 | 0.4% | Feb 29, 2024 | Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force E... |
| CVE-2024-26131 | HIGH | 7.8 | 0.5% | Feb 29, 2024 | Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redire... |
| CVE-2024-25932 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows C... |
| CVE-2024-25931 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.... |
| CVE-2024-25930 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Cu... |
| CVE-2024-25833 | CRITICAL | 9.8 | 2.8% | Feb 29, 2024 | F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious ac... |
| CVE-2024-25832 | HIGH | 8.8 | 12.8% | Feb 29, 2024 | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to ... |
| CVE-2024-25831 | MEDIUM | 5.4 | 0.6% | Feb 29, 2024 | F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input ... |
| CVE-2024-25830 | CRITICAL | 9.8 | 24.0% | Feb 29, 2024 | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una... |
| CVE-2024-25713 | HIGH | 8.6 | 1.8% | Feb 29, 2024 | yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function l... |
| CVE-2024-25712 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandle... |
| CVE-2024-25262 | HIGH | 8.1 | 0.9% | Feb 29, 2024 | texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulne... |
| CVE-2024-25128 | CRITICAL | 9.1 | 0.9% | Feb 29, 2024 | Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TY... |
| CVE-2024-25065 | CRITICAL | 9.1 | 47.7% | Feb 29, 2024 | Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.1... |
| CVE-2024-25006 | HIGH | 8.1 | 1.0% | Feb 29, 2024 | XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to adm... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now