2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26468 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b6... |
| CVE-2024-26467 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams befo... |
| CVE-2024-26466 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform... |
| CVE-2024-26465 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before... |
| CVE-2024-25925 | CRITICAL | 9.8 | 0.6% | Feb 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees ... |
| CVE-2024-25913 | CRITICAL | 9.8 | 0.6% | Feb 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a ... |
| CVE-2024-25909 | HIGH | 8.8 | 0.6% | Feb 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media ... |
| CVE-2024-25763 | MEDIUM | 5.5 | 0.5% | Feb 26, 2024 | openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c. |
| CVE-2024-25760 | — | — | — | Feb 26, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-25410 | MEDIUM | 6.5 | 0.6% | Feb 26, 2024 | flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php. |
| CVE-2024-25344 | MEDIUM | 6.1 | 0.7% | Feb 26, 2024 | Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remto... |
| CVE-2024-25082 | MEDIUM | 6.5 | 1.9% | Feb 26, 2024 | Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. |
| CVE-2024-25081 | MEDIUM | 4.2 | 1.1% | Feb 26, 2024 | Splinefont in FontForge through 20230101 allows command injection via crafted filenames. |
| CVE-2024-24714 | HIGH | 7.2 | 0.6% | Feb 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons... |
| CVE-2024-24568 | MEDIUM | 5.3 | 0.6% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P... |
| CVE-2024-23839 | HIGH | 8.1 | 0.8% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P... |
| CVE-2024-23837 | HIGH | 7.5 | 1.2% | Feb 26, 2024 | LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP hea... |
| CVE-2024-23836 | HIGH | 7.5 | 1.2% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-23835 | HIGH | 7.5 | 0.9% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P... |
| CVE-2024-23605 | CRITICAL | 9.8 | 1.3% | Feb 26, 2024 | A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2... |
| CVE-2024-23496 | CRITICAL | 9.8 | 1.3% | Feb 26, 2024 | A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 1... |
| CVE-2024-22873 | HIGH | 8.1 | 0.7% | Feb 26, 2024 | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subs... |
| CVE-2024-22371 | HIGH | 7.5 | 0.7% | Feb 26, 2024 | Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that expo... |
| CVE-2024-22201 | HIGH | 7.5 | 1.4% | Feb 26, 2024 | Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will... |
| CVE-2024-21836 | CRITICAL | 9.8 | 1.3% | Feb 26, 2024 | A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now