2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0890 | CRITICAL | 9.8 | 0.7% | Jan 25, 2024 | A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function ... |
| CVE-2024-0889 | HIGH | 7.5 | 1.4% | Jan 25, 2024 | A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unkn... |
| CVE-2024-23055 | MEDIUM | 6.1 | 1.2% | Jan 25, 2024 | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper... |
| CVE-2024-22922 | CRITICAL | 9.8 | 1.0% | Jan 25, 2024 | An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a cra... |
| CVE-2024-0888 | HIGH | 7.5 | 1.1% | Jan 25, 2024 | A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown par... |
| CVE-2024-0887 | HIGH | 7.5 | 1.1% | Jan 25, 2024 | A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue... |
| CVE-2024-0886 | MEDIUM | 5.5 | 0.4% | Jan 25, 2024 | A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerabi... |
| CVE-2024-24399 | HIGH | 7.2 | 15.6% | Jan 25, 2024 | An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by ... |
| CVE-2024-22639 | MEDIUM | 6.1 | 0.4% | Jan 25, 2024 | iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) fi... |
| CVE-2024-22638 | CRITICAL | 9.8 | 1.6% | Jan 25, 2024 | liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_d... |
| CVE-2024-22637 | MEDIUM | 6.1 | 0.4% | Jan 25, 2024 | Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form... |
| CVE-2024-22636 | HIGH | 8.8 | 1.3% | Jan 25, 2024 | PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. Th... |
| CVE-2024-22635 | MEDIUM | 6.1 | 0.5% | Jan 25, 2024 | WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /Web... |
| CVE-2024-0885 | HIGH | 7.5 | 1.4% | Jan 25, 2024 | A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the c... |
| CVE-2024-0884 | CRITICAL | 9.8 | 0.6% | Jan 25, 2024 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical.... |
| CVE-2024-23817 | MEDIUM | 6.1 | 0.6% | Jan 25, 2024 | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 1... |
| CVE-2024-23656 | HIGH | 7.5 | 0.4% | Jan 25, 2024 | Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with... |
| CVE-2024-23655 | MEDIUM | 5.3 | 0.8% | Jan 25, 2024 | Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to s... |
| CVE-2024-21630 | MEDIUM | 4.3 | 0.4% | Jan 25, 2024 | Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applie... |
| CVE-2024-0883 | CRITICAL | 9.8 | 0.6% | Jan 25, 2024 | A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critic... |
| CVE-2024-0882 | HIGH | 7.5 | 0.8% | Jan 25, 2024 | A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown ... |
| CVE-2024-0880 | HIGH | 8.8 | 0.4% | Jan 25, 2024 | A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unkno... |
| CVE-2024-22749 | HIGH | 7.8 | 0.5% | Jan 25, 2024 | GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in ... |
| CVE-2024-22529 | CRITICAL | 9.8 | 1.7% | Jan 25, 2024 | TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of fo... |
| CVE-2024-0822 | HIGH | 7.5 | 0.7% | Jan 25, 2024 | An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system w... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now