2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22234 | HIGH | 7.4 | 0.7% | Feb 20, 2024 | In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to bro... |
| CVE-2024-1559 | MEDIUM | 6.1 | 0.4% | Feb 20, 2024 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in ... |
| CVE-2024-1510 | MEDIUM | 5.4 | 0.5% | Feb 20, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-22019 | HIGH | 7.5 | 3.2% | Feb 20, 2024 | A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encodin... |
| CVE-2024-21896 | CRITICAL | 9.8 | 1.3% | Feb 20, 2024 | The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the ... |
| CVE-2024-21892 | HIGH | 7.8 | 0.6% | Feb 20, 2024 | On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the pro... |
| CVE-2024-21891 | HIGH | 8.8 | 1.2% | Feb 20, 2024 | Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be ov... |
| CVE-2024-21890 | MEDIUM | 6.5 | 0.9% | Feb 20, 2024 | The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last charac... |
| CVE-2024-0715 | CRITICAL | 9.8 | 0.5% | Feb 20, 2024 | Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue a... |
| CVE-2024-1648 | HIGH | 7.5 | 0.7% | Feb 20, 2024 | electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible beca... |
| CVE-2024-1647 | HIGH | 7.5 | 0.7% | Feb 20, 2024 | Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because... |
| CVE-2024-1651 | CRITICAL | 9.8 | 34.0% | Feb 20, 2024 | Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application i... |
| CVE-2024-1644 | HIGH | 8.8 | 0.9% | Feb 20, 2024 | Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LF... |
| CVE-2024-1297 | HIGH | 7.2 | 2.8% | Feb 20, 2024 | Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vu... |
| CVE-2024-26134 | HIGH | 7.5 | 1.2% | Feb 19, 2024 | cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format... |
| CVE-2024-26129 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vu... |
| CVE-2024-1638 | CRITICAL | 9.1 | 0.4% | Feb 19, 2024 | The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characte... |
| CVE-2024-1635 | HIGH | 7.5 | 4.6% | Feb 19, 2024 | A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protoco... |
| CVE-2024-25640 | MEDIUM | 5.4 | 0.3% | Feb 19, 2024 | Iris is a web collaborative platform that helps incident responders share technical details during investigations. A sto... |
| CVE-2024-25636 | HIGH | 8.8 | 0.7% | Feb 19, 2024 | Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when... |
| CVE-2024-25635 | HIGH | 8.8 | 0.7% | Feb 19, 2024 | alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the gener... |
| CVE-2024-25634 | MEDIUM | 6.5 | 0.7% | Feb 19, 2024 | alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other... |
| CVE-2024-25626 | CRITICAL | 9.8 | 1.2% | Feb 19, 2024 | Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless... |
| CVE-2024-25983 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard ... |
| CVE-2024-25982 | HIGH | 8.8 | 0.5% | Feb 19, 2024 | The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now