2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25130 | MEDIUM | 6.5 | 0.5% | Feb 22, 2024 | Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.9... |
| CVE-2024-25129 | MEDIUM | 5.5 | 0.8% | Feb 22, 2024 | The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser u... |
| CVE-2024-22547 | MEDIUM | 4.7 | 0.4% | Feb 22, 2024 | WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2024-25802 | CRITICAL | 9.8 | 0.6% | Feb 22, 2024 | SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attac... |
| CVE-2024-24817 | MEDIUM | 5.3 | 0.4% | Feb 22, 2024 | Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discuss... |
| CVE-2024-26592 | HIGH | 7.8 | 0.8% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() ... |
| CVE-2024-26591 | MEDIUM | 5.5 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix re-attachment branch in bpf_tracing_prog_a... |
| CVE-2024-26590 | MEDIUM | 5.5 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix inconsistent per-file compression format... |
| CVE-2024-26589 | HIGH | 7.8 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS... |
| CVE-2024-26588 | HIGH | 7.8 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Prevent out-of-bounds memory access... |
| CVE-2024-26587 | MEDIUM | 5.5 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PH... |
| CVE-2024-26586 | MEDIUM | 6.7 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption Whe... |
| CVE-2024-25828 | MEDIUM | 4.9 | 0.6% | Feb 22, 2024 | cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php. |
| CVE-2024-26284 | MEDIUM | 6.1 | 0.3% | Feb 22, 2024 | Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, ... |
| CVE-2024-26283 | HIGH | 7.8 | 0.3% | Feb 22, 2024 | An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external... |
| CVE-2024-26282 | HIGH | 7.1 | 0.3% | Feb 22, 2024 | Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. Th... |
| CVE-2024-26281 | MEDIUM | 4.7 | 0.3% | Feb 22, 2024 | Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur... |
| CVE-2024-25851 | HIGH | 8 | 1.9% | Feb 22, 2024 | Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in... |
| CVE-2024-25850 | CRITICAL | 9.8 | 19.1% | Feb 22, 2024 | Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter |
| CVE-2024-1563 | HIGH | 8.1 | 0.4% | Feb 22, 2024 | An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external... |
| CVE-2024-26445 | MEDIUM | 6.1 | 0.2% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_pla... |
| CVE-2024-26352 | HIGH | 8.8 | 0.3% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places... |
| CVE-2024-26351 | MEDIUM | 6.1 | 0.2% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_pla... |
| CVE-2024-26350 | HIGH | 8.8 | 0.3% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_con... |
| CVE-2024-26349 | MEDIUM | 4.3 | 0.3% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_tra... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now