2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26295 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-26294 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-1866 | — | — | — | Feb 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d... |
| CVE-2024-1865 | — | — | — | Feb 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d... |
| CVE-2024-1864 | — | — | — | Feb 27, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2813. Reason: This candidate is a d... |
| CVE-2024-0763 | HIGH | 8.1 | 0.9% | Feb 27, 2024 | Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path t... |
| CVE-2024-24027 | HIGH | 7.2 | 0.7% | Feb 27, 2024 | SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Dist... |
| CVE-2024-27099 | CRITICAL | 9.8 | 1.4% | Feb 27, 2024 | The uAMQP is a C library for AMQP 1.0 communication to Azure Cloud Services. When processing an incorrect `AMQP_VALUE` f... |
| CVE-2024-25846 | CRITICAL | 9.1 | 0.8% | Feb 27, 2024 | In the module "Product Catalog (CSV, Excel) Import" (simpleimportproduct) <= 6.7.0 from MyPrestaModules for PrestaShop, ... |
| CVE-2024-25843 | CRITICAL | 9.8 | 0.6% | Feb 27, 2024 | In the module "Import/Update Bulk Product from any Csv/Excel File Pro" (ba_importer) up to version 1.1.28 from Buy Addon... |
| CVE-2024-25841 | MEDIUM | 5.9 | 0.4% | Feb 27, 2024 | In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated cust... |
| CVE-2024-25840 | HIGH | 7.5 | 0.6% | Feb 27, 2024 | In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World ... |
| CVE-2024-24323 | HIGH | 7.2 | 0.7% | Feb 27, 2024 | SQL injection vulnerability in linlinjava litemall v.1.8.0 allows a remote attacker to obtain sensitive information via ... |
| CVE-2024-21742 | MEDIUM | 5.3 | 1.1% | Feb 27, 2024 | Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. Thi... |
| CVE-2024-1926 | CRITICAL | 9.8 | 0.6% | Feb 27, 2024 | A vulnerability was found in SourceCodester Free and Open Source Inventory Management System 1.0. It has been rated as c... |
| CVE-2024-1925 | HIGH | 8.1 | 0.6% | Feb 27, 2024 | A vulnerability was found in Ctcms 2.1.2. It has been declared as critical. This vulnerability affects unknown code of t... |
| CVE-2024-1924 | MEDIUM | 5.3 | 0.5% | Feb 27, 2024 | A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect... |
| CVE-2024-27508 | HIGH | 7.5 | 0.7% | Feb 27, 2024 | Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c. |
| CVE-2024-26464 | — | — | — | Feb 27, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-26144 | MEDIUM | 5.3 | 1.1% | Feb 27, 2024 | Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information lea... |
| CVE-2024-26143 | MEDIUM | 6.1 | 1.0% | Feb 27, 2024 | Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action... |
| CVE-2024-26142 | HIGH | 7.5 | 1.5% | Feb 27, 2024 | Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept h... |
| CVE-2024-25400 | CRITICAL | 9.8 | 0.7% | Feb 27, 2024 | Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third partie... |
| CVE-2024-25399 | MEDIUM | 6.1 | 0.3% | Feb 27, 2024 | Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php. |
| CVE-2024-25398 | HIGH | 7.5 | 0.7% | Feb 27, 2024 | In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service con... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now