2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24755 | MEDIUM | 5.3 | 0.4% | Feb 1, 2024 | discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP... |
| CVE-2024-1040 | MEDIUM | 4.4 | 0.1% | Feb 1, 2024 | Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by... |
| CVE-2024-1039 | CRITICAL | 9.8 | 0.7% | Feb 1, 2024 | Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an ... |
| CVE-2024-0325 | HIGH | 7.8 | 0.8% | Feb 1, 2024 | In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins. |
| CVE-2024-24945 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att... |
| CVE-2024-24041 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att... |
| CVE-2024-24569 | MEDIUM | 4.8 | 0.6% | Feb 1, 2024 | The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurre... |
| CVE-2024-23645 | MEDIUM | 6.1 | 0.9% | Feb 1, 2024 | GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. U... |
| CVE-2024-1167 | HIGH | 7.5 | 0.5% | Feb 1, 2024 | When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur. |
| CVE-2024-24570 | MEDIUM | 6.1 | 0.7% | Feb 1, 2024 | Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing f... |
| CVE-2024-24561 | CRITICAL | 9.8 | 0.9% | Feb 1, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds... |
| CVE-2024-24557 | HIGH | 7.8 | 0.3% | Feb 1, 2024 | Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system i... |
| CVE-2024-23832 | CRITICAL | 9.8 | 1.9% | Feb 1, 2024 | Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for aut... |
| CVE-2024-24754 | CRITICAL | 9.8 | 0.6% | Feb 1, 2024 | Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ... |
| CVE-2024-24753 | MEDIUM | 6.5 | 0.4% | Feb 1, 2024 | Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it do... |
| CVE-2024-24752 | MEDIUM | 6.5 | 0.8% | Feb 1, 2024 | Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ... |
| CVE-2024-1141 | MEDIUM | 5.5 | 0.2% | Feb 1, 2024 | A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-s... |
| CVE-2024-0704 | — | — | — | Feb 1, 2024 | Rejected reason: very low impact - impractical to correct |
| CVE-2024-24062 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role. |
| CVE-2024-24061 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add. |
| CVE-2024-24060 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user. |
| CVE-2024-24059 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded file... |
| CVE-2024-0935 | HIGH | 7.5 | 0.4% | Feb 1, 2024 | Insertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Releas... |
| CVE-2024-22449 | HIGH | 7.8 | 0.2% | Feb 1, 2024 | Dell PowerScale OneFS versions 9.0.0.x through 9.6.0.x contains a missing authentication for critical function vulnerab... |
| CVE-2024-22430 | MEDIUM | 5.5 | 0.1% | Feb 1, 2024 | Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local l... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now