2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0849 | MEDIUM | 5 | 0.2% | Feb 7, 2024 | Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to ... |
| CVE-2024-1269 | MEDIUM | 6.1 | 0.7% | Feb 7, 2024 | A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulne... |
| CVE-2024-1268 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | A vulnerability, which was classified as critical, was found in CodeAstro Restaurant POS System 1.0. This affects an unk... |
| CVE-2024-24019 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset... |
| CVE-2024-22022 | HIGH | 8.8 | 0.7% | Feb 7, 2024 | Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to a... |
| CVE-2024-22021 | MEDIUM | 4.3 | 0.4% | Feb 7, 2024 | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retri... |
| CVE-2024-1267 | MEDIUM | 6.1 | 0.4% | Feb 7, 2024 | A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by... |
| CVE-2024-1266 | MEDIUM | 6.1 | 0.5% | Feb 7, 2024 | A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vuln... |
| CVE-2024-24004 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon... |
| CVE-2024-24002 | CRITICAL | 9.8 | 0.8% | Feb 7, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseRespons... |
| CVE-2024-24001 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRe... |
| CVE-2024-1284 | CRITICAL | 9.8 | 1.1% | Feb 7, 2024 | Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-1283 | CRITICAL | 9.8 | 1.5% | Feb 7, 2024 | Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit h... |
| CVE-2024-1265 | MEDIUM | 4.8 | 0.5% | Feb 7, 2024 | A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an u... |
| CVE-2024-1264 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability... |
| CVE-2024-0971 | MEDIUM | 6.5 | 0.8% | Feb 7, 2024 | A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter sca... |
| CVE-2024-0955 | MEDIUM | 4.8 | 0.6% | Feb 7, 2024 | A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus a... |
| CVE-2024-24255 | MEDIUM | 4.2 | 0.3% | Feb 6, 2024 | A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows... |
| CVE-2024-22388 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Certain configuration available in the communication channel for encoders could expose sensitive data when reader config... |
| CVE-2024-1263 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function ac... |
| CVE-2024-1262 | CRITICAL | 9.8 | 0.6% | Feb 6, 2024 | A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the... |
| CVE-2024-24680 | HIGH | 7.5 | 1.6% | Feb 6, 2024 | An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma templa... |
| CVE-2024-24577 | CRITICAL | 9.8 | 1.5% | Feb 6, 2024 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing... |
| CVE-2024-24575 | HIGH | 7.5 | 1.4% | Feb 6, 2024 | libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing... |
| CVE-2024-24254 | MEDIUM | 4.2 | 0.4% | Feb 6, 2024 | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now