2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23756 | HIGH | 7.5 | 0.6% | Feb 8, 2024 | The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated... |
| CVE-2024-24115 | MEDIUM | 5.4 | 0.4% | Feb 8, 2024 | A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated ... |
| CVE-2024-23660 | HIGH | 7.5 | 0.6% | Feb 8, 2024 | The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezo... |
| CVE-2024-22836 | CRITICAL | 9.8 | 30.0% | Feb 8, 2024 | An OS command injection vulnerability exists in Akaunting v3.1.3 and earlier. An attacker can manipulate the company loc... |
| CVE-2024-1329 | HIGH | 7.5 | 0.6% | Feb 8, 2024 | HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file wri... |
| CVE-2024-0242 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access ... |
| CVE-2024-24215 | MEDIUM | 5.3 | 0.5% | Feb 8, 2024 | An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configu... |
| CVE-2024-23764 | MEDIUM | 6.7 | 0.2% | Feb 8, 2024 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, With... |
| CVE-2024-22795 | HIGH | 7 | 0.3% | Feb 8, 2024 | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privi... |
| CVE-2024-24321 | CRITICAL | 9.8 | 2.4% | Feb 8, 2024 | An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 pa... |
| CVE-2024-24213 | CRITICAL | 9.8 | 0.8% | Feb 8, 2024 | Supabase PostgreSQL v15.1 was discovered to contain a SQL injection vulnerability via the component /pg_meta/default/que... |
| CVE-2024-25191 | CRITICAL | 9.8 | 0.9% | Feb 8, 2024 | php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent... |
| CVE-2024-25190 | CRITICAL | 9.8 | 0.9% | Feb 8, 2024 | l8w8jwt 2.2.1 uses memcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent... |
| CVE-2024-25189 | CRITICAL | 9.8 | 1.0% | Feb 8, 2024 | libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it easier to bypass authent... |
| CVE-2024-24834 | MEDIUM | 4.8 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – ... |
| CVE-2024-24878 | MEDIUM | 6.1 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | We... |
| CVE-2024-24877 | MEDIUM | 6.1 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Lt... |
| CVE-2024-24871 | MEDIUM | 5.4 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq B... |
| CVE-2024-24836 | MEDIUM | 5.4 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data... |
| CVE-2024-24113 | HIGH | 8.8 | 0.6% | Feb 8, 2024 | xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control ex... |
| CVE-2024-1312 | MEDIUM | 4.7 | 0.2% | Feb 8, 2024 | A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same... |
| CVE-2024-1150 | MEDIUM | 5.5 | 0.1% | Feb 8, 2024 | Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Mani... |
| CVE-2024-1149 | MEDIUM | 5.5 | 0.1% | Feb 8, 2024 | Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software ... |
| CVE-2024-0985 | HIGH | 8 | 1.5% | Feb 8, 2024 | Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrar... |
| CVE-2024-24885 | MEDIUM | 5.4 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lê Văn Toản Woocom... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now