2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25940 | MEDIUM | 6.3 | 0.5% | Feb 15, 2024 | `bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected v... |
| CVE-2024-25559 | MEDIUM | 4.7 | 0.4% | Feb 15, 2024 | URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request... |
| CVE-2024-1488 | HIGH | 7.3 | 0.3% | Feb 15, 2024 | A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound grou... |
| CVE-2024-26264 | CRITICAL | 9.8 | 0.8% | Feb 15, 2024 | EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page... |
| CVE-2024-26263 | HIGH | 7.5 | 0.4% | Feb 15, 2024 | EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse speci... |
| CVE-2024-26262 | HIGH | 8.8 | 0.8% | Feb 15, 2024 | EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remot... |
| CVE-2024-26261 | CRITICAL | 9.8 | 0.7% | Feb 15, 2024 | The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulner... |
| CVE-2024-26260 | CRITICAL | 9.8 | 1.6% | Feb 15, 2024 | The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, all... |
| CVE-2024-1523 | HIGH | 8.8 | 0.8% | Feb 15, 2024 | EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authent... |
| CVE-2024-25620 | MEDIUM | 6.4 | 0.6% | Feb 15, 2024 | Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm cli... |
| CVE-2024-24301 | HIGH | 8.8 | 2.1% | Feb 14, 2024 | Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allo... |
| CVE-2024-24300 | CRITICAL | 9.8 | 0.8% | Feb 14, 2024 | 4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardle... |
| CVE-2024-1471 | MEDIUM | 4.8 | 0.4% | Feb 14, 2024 | An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Sec... |
| CVE-2024-1367 | HIGH | 7.2 | 1.6% | Feb 14, 2024 | A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the S... |
| CVE-2024-25619 | MEDIUM | 4.3 | 0.4% | Feb 14, 2024 | Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the ... |
| CVE-2024-25618 | HIGH | 7.4 | 0.5% | Feb 14, 2024 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configur... |
| CVE-2024-25617 | HIGH | 7.5 | 88.9% | Feb 14, 2024 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into ... |
| CVE-2024-25165 | HIGH | 7.8 | 0.5% | Feb 14, 2024 | A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex. |
| CVE-2024-1482 | MEDIUM | 6.5 | 0.4% | Feb 14, 2024 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create n... |
| CVE-2024-25301 | HIGH | 7.2 | 1.5% | Feb 14, 2024 | Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.... |
| CVE-2024-25300 | MEDIUM | 4.8 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-0011 | MEDIUM | 6.1 | 0.4% | Feb 14, 2024 | A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software... |
| CVE-2024-0010 | MEDIUM | 6.1 | 0.5% | Feb 14, 2024 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS so... |
| CVE-2024-0009 | MEDIUM | 6.3 | 0.2% | Feb 14, 2024 | An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enable... |
| CVE-2024-0008 | HIGH | 8.8 | 0.5% | Feb 14, 2024 | Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, maki... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now