2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25109 | MEDIUM | 5.4 | 0.4% | Feb 9, 2024 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface ... |
| CVE-2024-24828 | HIGH | 7.8 | 0.2% | Feb 9, 2024 | pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written t... |
| CVE-2024-23327 | HIGH | 7.5 | 0.7% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, t... |
| CVE-2024-23325 | HIGH | 7.5 | 0.8% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that i... |
| CVE-2024-23324 | HIGH | 7.5 | 0.6% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections... |
| CVE-2024-23323 | MEDIUM | 5.3 | 0.5% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result... |
| CVE-2024-23322 | HIGH | 7.5 | 0.7% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same int... |
| CVE-2024-21624 | MEDIUM | 6.5 | 0.5% | Feb 9, 2024 | nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to... |
| CVE-2024-1404 | HIGH | 7.5 | 0.8% | Feb 9, 2024 | A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unkno... |
| CVE-2024-1246 | MEDIUM | 4.8 | 0.5% | Feb 9, 2024 | Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficie... |
| CVE-2024-1245 | MEDIUM | 4.8 | 0.4% | Feb 9, 2024 | Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administra... |
| CVE-2024-1247 | MEDIUM | 4.8 | 1.2% | Feb 9, 2024 | Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient val... |
| CVE-2024-1402 | MEDIUM | 4.3 | 0.5% | Feb 9, 2024 | Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom ... |
| CVE-2024-25454 | MEDIUM | 5.5 | 0.2% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function. |
| CVE-2024-25453 | MEDIUM | 5.5 | 0.3% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function. |
| CVE-2024-25452 | MEDIUM | 5.5 | 0.2% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. |
| CVE-2024-25451 | MEDIUM | 6.5 | 0.5% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function. |
| CVE-2024-25450 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts(). |
| CVE-2024-25448 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow ... |
| CVE-2024-25447 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer ove... |
| CVE-2024-25446 | HIGH | 7.8 | 0.4% | Feb 9, 2024 | An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer over... |
| CVE-2024-25445 | HIGH | 7.8 | 0.3% | Feb 9, 2024 | Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure. |
| CVE-2024-25443 | HIGH | 7.8 | 0.3% | Feb 9, 2024 | An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-... |
| CVE-2024-25442 | HIGH | 7.8 | 0.4% | Feb 9, 2024 | An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap bu... |
| CVE-2024-24776 | MEDIUM | 4.3 | 0.3% | Feb 9, 2024 | Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in chan... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now