2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23204 | HIGH | 7.5 | 1.8% | Jan 23, 2024 | The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.... |
| CVE-2024-23203 | HIGH | 7.5 | 0.9% | Jan 23, 2024 | The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.... |
| CVE-2024-23345 | MEDIUM | 5.4 | 0.4% | Jan 23, 2024 | Nautobot is a Network Source of Truth and Network Automation Platform built as a web application. All users of Nautobot... |
| CVE-2024-23342 | HIGH | 7.4 | 1.0% | Jan 23, 2024 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El... |
| CVE-2024-23340 | MEDIUM | 5.3 | 0.7% | Jan 22, 2024 | @hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server h... |
| CVE-2024-23339 | MEDIUM | 6.5 | 1.0% | Jan 22, 2024 | hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0... |
| CVE-2024-23678 | HIGH | 8.8 | 0.2% | Jan 22, 2024 | In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path inpu... |
| CVE-2024-23677 | MEDIUM | 5.3 | 0.4% | Jan 22, 2024 | In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applica... |
| CVE-2024-23676 | LOW | 3.5 | 0.3% | Jan 22, 2024 | In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index ... |
| CVE-2024-23675 | MEDIUM | 6.5 | 0.4% | Jan 22, 2024 | In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permission... |
| CVE-2024-0606 | MEDIUM | 6.1 | 0.3% | Jan 22, 2024 | An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascr... |
| CVE-2024-0605 | HIGH | 7.5 | 0.4% | Jan 22, 2024 | Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sit... |
| CVE-2024-0430 | MEDIUM | 5.5 | 0.2% | Jan 22, 2024 | IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL... |
| CVE-2024-0784 | CRITICAL | 9.8 | 0.7% | Jan 22, 2024 | A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function ... |
| CVE-2024-0783 | CRITICAL | 9.8 | 1.2% | Jan 22, 2024 | A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects s... |
| CVE-2024-0204 | CRITICAL | 9.8 | 95.1% | Jan 22, 2024 | Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via ... |
| CVE-2024-0782 | MEDIUM | 6.1 | 0.6% | Jan 22, 2024 | A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vu... |
| CVE-2024-0781 | MEDIUM | 6.1 | 0.5% | Jan 22, 2024 | A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects a... |
| CVE-2024-0778 | CRITICAL | 9.8 | 32.1% | Jan 22, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S ... |
| CVE-2024-22895 | HIGH | 8.8 | 0.8% | Jan 22, 2024 | DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php. |
| CVE-2024-0706 | — | — | — | Jan 22, 2024 | Rejected reason: ***REJECT*** This was a false positive report. |
| CVE-2024-22233 | HIGH | 7.5 | 1.0% | Jan 22, 2024 | In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that... |
| CVE-2024-0775 | HIGH | 7.1 | 0.2% | Jan 22, 2024 | A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a... |
| CVE-2024-22113 | MEDIUM | 6.1 | 0.4% | Jan 22, 2024 | Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote ... |
| CVE-2024-21484 | MEDIUM | 5.9 | 1.0% | Jan 22, 2024 | Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now