2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22729 | CRITICAL | 9.8 | 70.8% | Jan 25, 2024 | NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter ... |
| CVE-2024-22432 | MEDIUM | 6.5 | 0.1% | Jan 25, 2024 | Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup dura... |
| CVE-2024-0879 | MEDIUM | 4.3 | 0.4% | Jan 25, 2024 | Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is ... |
| CVE-2024-23855 | MEDIUM | 6.1 | 0.4% | Jan 25, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n... |
| CVE-2024-23307 | HIGH | 7.8 | 0.6% | Jan 25, 2024 | Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) a... |
| CVE-2024-22099 | MEDIUM | 5.5 | 0.6% | Jan 25, 2024 | NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows O... |
| CVE-2024-23985 | HIGH | 7.5 | 3.6% | Jan 25, 2024 | EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command. |
| CVE-2024-0625 | MEDIUM | 4.8 | 0.4% | Jan 25, 2024 | The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notifica... |
| CVE-2024-0688 | MEDIUM | 4.8 | 0.3% | Jan 25, 2024 | The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings i... |
| CVE-2024-0624 | MEDIUM | 5.3 | 1.0% | Jan 25, 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab... |
| CVE-2024-0617 | MEDIUM | 5.3 | 0.5% | Jan 25, 2024 | The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-22751 | CRITICAL | 9.8 | 1.2% | Jan 24, 2024 | D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function. |
| CVE-2024-23646 | HIGH | 8.8 | 0.8% | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip... |
| CVE-2024-23644 | HIGH | 8.1 | 0.6% | Jan 24, 2024 | Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 ... |
| CVE-2024-23905 | MEDIUM | 5.4 | 0.6% | Jan 24, 2024 | Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protecti... |
| CVE-2024-23904 | HIGH | 7.5 | 0.9% | Jan 24, 2024 | Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' chara... |
| CVE-2024-23903 | MEDIUM | 5.3 | 0.5% | Jan 24, 2024 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when ch... |
| CVE-2024-23902 | MEDIUM | 4.3 | 0.3% | Jan 24, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier... |
| CVE-2024-23901 | MEDIUM | 6.5 | 0.5% | Jan 24, 2024 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared w... |
| CVE-2024-23900 | MEDIUM | 4.3 | 0.7% | Jan 24, 2024 | Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configur... |
| CVE-2024-23899 | MEDIUM | 6.5 | 1.3% | Jan 24, 2024 | Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replace... |
| CVE-2024-23898 | HIGH | 8.8 | 66.9% | Jan 24, 2024 | Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin valid... |
| CVE-2024-23897 | CRITICAL | 9.8 | 100.0% | Jan 24, 2024 | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an... |
| CVE-2024-23649 | MEDIUM | 6.5 | 0.5% | Jan 24, 2024 | Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users ca... |
| CVE-2024-23648 | HIGH | 8.8 | 0.8% | Jan 24, 2024 | Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now