2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25876 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr... |
| CVE-2024-25875 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr... |
| CVE-2024-25874 | MEDIUM | 5.4 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to exec... |
| CVE-2024-25873 | MEDIUM | 5.4 | 0.5% | Feb 22, 2024 | Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote m... |
| CVE-2024-23094 | HIGH | 8.8 | 0.3% | Feb 22, 2024 | Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_med... |
| CVE-2024-26287 | — | — | — | Feb 22, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-25021 | HIGH | 8.4 | 0.3% | Feb 22, 2024 | IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execut... |
| CVE-2024-1104 | HIGH | 7.5 | 0.7% | Feb 22, 2024 | An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all us... |
| CVE-2024-0220 | HIGH | 8.1 | 0.4% | Feb 22, 2024 | B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the... |
| CVE-2024-26578 | MEDIUM | 5.9 | 0.9% | Feb 22, 2024 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ... |
| CVE-2024-23349 | MEDIUM | 5.4 | 1.1% | Feb 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This... |
| CVE-2024-22393 | CRITICAL | 9.1 | 2.5% | Feb 22, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through... |
| CVE-2024-26491 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CM... |
| CVE-2024-26490 | MEDIUM | 5.4 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execut... |
| CVE-2024-26489 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allo... |
| CVE-2024-1053 | MEDIUM | 4.3 | 0.4% | Feb 22, 2024 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2024-0903 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera... |
| CVE-2024-27283 | HIGH | 7.2 | 0.7% | Feb 22, 2024 | A vulnerability was discovered in Veritas eDiscovery Platform before 10.2.5. The application administrator can upload po... |
| CVE-2024-26484 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers... |
| CVE-2024-26483 | HIGH | 8.8 | 1.0% | Feb 22, 2024 | An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbit... |
| CVE-2024-26482 | HIGH | 7.1 | 0.3% | Feb 22, 2024 | An HTML injection vulnerability exists in the Edit Content Layout module of Kirby CMS v4.1.0. NOTE: the vendor disputes ... |
| CVE-2024-26481 | MEDIUM | 4.7 | 0.4% | Feb 22, 2024 | Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter. |
| CVE-2024-25801 | MEDIUM | 6.1 | 0.3% | Feb 22, 2024 | SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload i... |
| CVE-2024-23137 | HIGH | 7.8 | 1.0% | Feb 22, 2024 | A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uni... |
| CVE-2024-23136 | HIGH | 7.8 | 0.4% | Feb 22, 2024 | A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk applications can be used to dereference a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now