2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25981 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all... |
| CVE-2024-25980 | MEDIUM | 5.3 | 0.5% | Feb 19, 2024 | Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other grou... |
| CVE-2024-25979 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | The URL parameters accepted by forum search were not limited to the allowed parameters. |
| CVE-2024-25978 | HIGH | 7.5 | 0.9% | Feb 19, 2024 | Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. |
| CVE-2024-1633 | LOW | 2 | 0.1% | Feb 19, 2024 | During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_... |
| CVE-2024-25625 | CRITICAL | 9.3 | 0.7% | Feb 19, 2024 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered... |
| CVE-2024-25623 | HIGH | 7.7 | 0.5% | Feb 19, 2024 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and... |
| CVE-2024-1597 | CRITICAL | 9.8 | 4.8% | Feb 19, 2024 | pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the ... |
| CVE-2024-1346 | MEDIUM | 5.5 | 0.4% | Feb 19, 2024 | Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to cal... |
| CVE-2024-1345 | MEDIUM | 5.5 | 0.2% | Feb 19, 2024 | Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to per... |
| CVE-2024-1344 | CRITICAL | 9.8 | 0.3% | Feb 19, 2024 | Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read... |
| CVE-2024-1343 | MEDIUM | 5.5 | 0.1% | Feb 19, 2024 | A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allow... |
| CVE-2024-1580 | HIGH | 8.8 | 1.8% | Feb 19, 2024 | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to mem... |
| CVE-2024-26308 | MEDIUM | 5.5 | 0.9% | Feb 19, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache ... |
| CVE-2024-25710 | MEDIUM | 5.5 | 0.4% | Feb 19, 2024 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apach... |
| CVE-2024-24722 | CRITICAL | 9.1 | 0.6% | Feb 19, 2024 | An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an att... |
| CVE-2024-26328 | MEDIUM | 6 | 0.3% | Feb 19, 2024 | An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIO... |
| CVE-2024-26327 | MEDIUM | 5.3 | 0.5% | Feb 19, 2024 | An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where ... |
| CVE-2024-26318 | MEDIUM | 6.1 | 0.4% | Feb 19, 2024 | Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / ... |
| CVE-2024-25113 | — | — | — | Feb 17, 2024 | Rejected reason: This CVE was misassigned. See CVE-2023-47623 for the canonical reference. |
| CVE-2024-22337 | MEDIUM | 5.5 | 0.2% | Feb 17, 2024 | IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall... |
| CVE-2024-22336 | MEDIUM | 5.5 | 0.2% | Feb 17, 2024 | IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall... |
| CVE-2024-22335 | MEDIUM | 5.5 | 0.2% | Feb 17, 2024 | IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall... |
| CVE-2024-1512 | CRITICAL | 9.8 | 77.7% | Feb 17, 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union base... |
| CVE-2024-0610 | CRITICAL | 9.8 | 0.7% | Feb 17, 2024 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now