2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24708 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a thro... |
| CVE-2024-24701 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-base... |
| CVE-2024-24155 | MEDIUM | 6.5 | 0.6% | Feb 29, 2024 | Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42a... |
| CVE-2024-24150 | MEDIUM | 6.5 | 0.8% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service vi... |
| CVE-2024-24149 | MEDIUM | 6.5 | 0.8% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service vi... |
| CVE-2024-24147 | MEDIUM | 6.5 | 0.7% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of servic... |
| CVE-2024-24146 | MEDIUM | 6.5 | 0.7% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service ... |
| CVE-2024-23946 | MEDIUM | 5.3 | 3.1% | Feb 29, 2024 | Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t... |
| CVE-2024-23807 | CRITICAL | 9.8 | 1.5% | Feb 29, 2024 | The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the sca... |
| CVE-2024-23519 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before ... |
| CVE-2024-23328 | CRITICAL | 9.1 | 1.2% | Feb 29, 2024 | Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase data... |
| CVE-2024-23302 | HIGH | 7.5 | 0.7% | Feb 29, 2024 | Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. |
| CVE-2024-23052 | CRITICAL | 9.8 | 4.9% | Feb 29, 2024 | An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-22939 | HIGH | 8.8 | 0.7% | Feb 29, 2024 | Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the syst... |
| CVE-2024-22936 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIM... |
| CVE-2024-22251 | MEDIUM | 4.4 | 0.2% | Feb 29, 2024 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). ... |
| CVE-2024-21726 | MEDIUM | 6.5 | 48.8% | Feb 29, 2024 | Inadequate content filtering leads to XSS vulnerabilities in various components. |
| CVE-2024-21725 | MEDIUM | 6.1 | 32.2% | Feb 29, 2024 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. |
| CVE-2024-21724 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. |
| CVE-2024-21723 | MEDIUM | 4.3 | 0.5% | Feb 29, 2024 | Inadequate parsing of URLs could result into an open redirect. |
| CVE-2024-21722 | MEDIUM | 6.3 | 0.5% | Feb 29, 2024 | The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modifi... |
| CVE-2024-20344 | MEDIUM | 5.3 | 0.8% | Feb 29, 2024 | A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersi... |
| CVE-2024-20321 | HIGH | 8.6 | 0.7% | Feb 29, 2024 | A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an una... |
| CVE-2024-20294 | MEDIUM | 6.6 | 0.3% | Feb 29, 2024 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software coul... |
| CVE-2024-20291 | MEDIUM | 5.8 | 0.9% | Feb 29, 2024 | A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now