2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24023 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ... |
| CVE-2024-24018 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset... |
| CVE-2024-24806 | HIGH | 7.3 | 2.0% | Feb 7, 2024 | libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/g... |
| CVE-2024-23448 | HIGH | 7.5 | 0.6% | Feb 7, 2024 | An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that index... |
| CVE-2024-1066 | MEDIUM | 6.5 | 0.6% | Feb 7, 2024 | An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and ... |
| CVE-2024-24488 | MEDIUM | 5.5 | 0.2% | Feb 7, 2024 | An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive informatio... |
| CVE-2024-22984 | — | — | — | Feb 7, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2024-23769 | MEDIUM | 5.5 | 0.2% | Feb 7, 2024 | Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacke... |
| CVE-2024-24824 | HIGH | 8.8 | 34.5% | Feb 7, 2024 | Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, ar... |
| CVE-2024-24823 | MEDIUM | 4.4 | 0.4% | Feb 7, 2024 | Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, re... |
| CVE-2024-24822 | CRITICAL | 9.1 | 0.5% | Feb 7, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can cr... |
| CVE-2024-24816 | MEDIUM | 6.1 | 1.7% | Feb 7, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability... |
| CVE-2024-24706 | MEDIUM | 4.3 | 0.2% | Feb 7, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1... |
| CVE-2024-24563 | CRITICAL | 9.8 | 1.5% | Feb 7, 2024 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, w... |
| CVE-2024-23806 | MEDIUM | 5.3 | 0.3% | Feb 7, 2024 | Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device ... |
| CVE-2024-20290 | HIGH | 7.5 | 33.6% | Feb 7, 2024 | A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a deni... |
| CVE-2024-20255 | HIGH | 7.1 | 0.6% | Feb 7, 2024 | A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow... |
| CVE-2024-20254 | HIGH | 8.8 | 0.8% | Feb 7, 2024 | Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ... |
| CVE-2024-20252 | HIGH | 8.8 | 0.8% | Feb 7, 2024 | Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow ... |
| CVE-2024-24815 | MEDIUM | 6.1 | 0.7% | Feb 7, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been disc... |
| CVE-2024-22012 | HIGH | 7.8 | 0.1% | Feb 7, 2024 | there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege ... |
| CVE-2024-25145 | MEDIUM | 5.4 | 0.6% | Feb 7, 2024 | Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 ... |
| CVE-2024-25143 | MEDIUM | 6.5 | 0.7% | Feb 7, 2024 | The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3... |
| CVE-2024-24812 | MEDIUM | 5.4 | 0.4% | Feb 7, 2024 | Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrate... |
| CVE-2024-24811 | CRITICAL | 9.8 | 0.9% | Feb 7, 2024 | SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unaut... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now