2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21383 | LOW | 3.3 | 0.4% | Jan 26, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-21382 | MEDIUM | 4.3 | 0.9% | Jan 26, 2024 | Microsoft Edge for Android Information Disclosure Vulnerability |
| CVE-2024-21326 | CRITICAL | 9.6 | 1.2% | Jan 26, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2024-0456 | MEDIUM | 4.3 | 0.5% | Jan 26, 2024 | An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 1... |
| CVE-2024-0402 | CRITICAL | 9.9 | 3.3% | Jan 26, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and... |
| CVE-2024-23630 | HIGH | 8.8 | 1.5% | Jan 26, 2024 | An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to... |
| CVE-2024-23629 | HIGH | 7.5 | 1.1% | Jan 26, 2024 | An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this ... |
| CVE-2024-23628 | HIGH | 8.8 | 3.2% | Jan 26, 2024 | A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote ... |
| CVE-2024-23627 | HIGH | 8.8 | 3.5% | Jan 26, 2024 | A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote a... |
| CVE-2024-23626 | HIGH | 8.8 | 3.5% | Jan 26, 2024 | A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker ... |
| CVE-2024-23625 | CRITICAL | 9.8 | 22.8% | Jan 26, 2024 | A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenti... |
| CVE-2024-23624 | CRITICAL | 9.8 | 26.0% | Jan 26, 2024 | A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker ... |
| CVE-2024-23622 | CRITICAL | 9.8 | 1.9% | Jan 26, 2024 | A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated... |
| CVE-2024-23621 | CRITICAL | 9.8 | 1.9% | Jan 26, 2024 | A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker ca... |
| CVE-2024-23620 | HIGH | 7.8 | 0.2% | Jan 26, 2024 | An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated ... |
| CVE-2024-23619 | CRITICAL | 9.8 | 1.7% | Jan 26, 2024 | A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacke... |
| CVE-2024-23618 | CRITICAL | 9.8 | 1.2% | Jan 26, 2024 | An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can ... |
| CVE-2024-23617 | HIGH | 8.8 | 1.7% | Jan 26, 2024 | A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthentic... |
| CVE-2024-23616 | CRITICAL | 9.8 | 1.9% | Jan 26, 2024 | A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous a... |
| CVE-2024-23615 | CRITICAL | 9.8 | 1.9% | Jan 26, 2024 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attac... |
| CVE-2024-23614 | CRITICAL | 9.8 | 1.6% | Jan 26, 2024 | A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attack... |
| CVE-2024-23613 | CRITICAL | 9.8 | 1.8% | Jan 26, 2024 | A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A... |
| CVE-2024-21620 | MEDIUM | 6.1 | 0.9% | Jan 25, 2024 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Junipe... |
| CVE-2024-21619 | HIGH | 7.5 | 0.9% | Jan 25, 2024 | A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sens... |
| CVE-2024-0891 | MEDIUM | 5.4 | 0.6% | Jan 25, 2024 | A vulnerability was found in hongmaple octopus 1.0. It has been declared as problematic. Affected by this vulnerability ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now