2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1899 | MEDIUM | 5.3 | 0.8% | Feb 26, 2024 | An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of servi... |
| CVE-2024-27084 | — | — | — | Feb 26, 2024 | Rejected reason: This CVE is a duplicate of CVE-2024-1631. |
| CVE-2024-26455 | HIGH | 7.5 | 0.7% | Feb 26, 2024 | fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c. |
| CVE-2024-25770 | MEDIUM | 4.3 | 0.6% | Feb 26, 2024 | libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. |
| CVE-2024-25768 | HIGH | 7.5 | 0.7% | Feb 26, 2024 | OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c. |
| CVE-2024-27088 | MEDIUM | 5.5 | 0.5% | Feb 26, 2024 | es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into ... |
| CVE-2024-27087 | MEDIUM | 5.4 | 0.3% | Feb 26, 2024 | Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that ... |
| CVE-2024-27081 | HIGH | 8.8 | 1.5% | Feb 26, 2024 | ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the... |
| CVE-2024-25767 | MEDIUM | 6.5 | 0.6% | Feb 26, 2024 | nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c. |
| CVE-2024-24402 | CRITICAL | 9.8 | 3.4% | Feb 26, 2024 | An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/n... |
| CVE-2024-24401 | CRITICAL | 9.8 | 45.9% | Feb 26, 2024 | SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payl... |
| CVE-2024-27456 | CRITICAL | 9.1 | 0.8% | Feb 26, 2024 | rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files. |
| CVE-2024-27455 | CRITICAL | 9.1 | 0.6% | Feb 26, 2024 | In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token wh... |
| CVE-2024-27454 | HIGH | 7.5 | 1.2% | Feb 26, 2024 | orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents. |
| CVE-2024-27447 | CRITICAL | 9.8 | 0.8% | Feb 26, 2024 | pretix before 2024.1.1 mishandles file validation. |
| CVE-2024-27444 | CRITICAL | 9.8 | 0.8% | Feb 26, 2024 | langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-... |
| CVE-2024-27359 | HIGH | 7.5 | 0.7% | Feb 26, 2024 | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when proce... |
| CVE-2024-27350 | MEDIUM | 5.9 | 0.3% | Feb 26, 2024 | Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug B... |
| CVE-2024-26606 | MEDIUM | 5.5 | 0.2% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)po... |
| CVE-2024-26605 | MEDIUM | 5.5 | 0.2% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last m... |
| CVE-2024-26604 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whethe... |
| CVE-2024-26603 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to faul... |
| CVE-2024-26602 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on s... |
| CVE-2024-26601 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed i... |
| CVE-2024-26600 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereferenc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now