2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22877 | MEDIUM | 5.4 | 0.3% | Jan 19, 2024 | StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This ... |
| CVE-2024-22876 | MEDIUM | 5.4 | 0.3% | Jan 19, 2024 | StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment ... |
| CVE-2024-0713 | — | — | — | Jan 19, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-28871. Reason: This candidate is a ... |
| CVE-2024-0712 | CRITICAL | 9.8 | 3.9% | Jan 19, 2024 | A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affect... |
| CVE-2024-21733 | MEDIUM | 5.3 | 14.3% | Jan 19, 2024 | Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache To... |
| CVE-2024-0705 | HIGH | 7.5 | 2.7% | Jan 19, 2024 | The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in ... |
| CVE-2024-23659 | MEDIUM | 6.1 | 0.4% | Jan 19, 2024 | SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/big... |
| CVE-2024-23387 | MEDIUM | 4.8 | 0.5% | Jan 19, 2024 | FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote a... |
| CVE-2024-22424 | HIGH | 8.3 | 0.4% | Jan 19, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.... |
| CVE-2024-22422 | HIGH | 7.5 | 1.0% | Jan 19, 2024 | AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use a... |
| CVE-2024-0696 | MEDIUM | 6.1 | 0.5% | Jan 18, 2024 | A vulnerability, which was classified as problematic, was found in AtroCore AtroPIM 1.8.4. This affects an unknown part ... |
| CVE-2024-0695 | MEDIUM | 5.3 | 1.0% | Jan 18, 2024 | A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue... |
| CVE-2024-0693 | HIGH | 7.5 | 1.3% | Jan 18, 2024 | A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is ... |
| CVE-2024-22418 | MEDIUM | 5.4 | 0.4% | Jan 18, 2024 | Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present ... |
| CVE-2024-22415 | CRITICAL | 9.8 | 0.5% | Jan 18, 2024 | jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +... |
| CVE-2024-22404 | MEDIUM | 4.3 | 0.5% | Jan 18, 2024 | Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected v... |
| CVE-2024-22402 | MEDIUM | 5.4 | 0.5% | Jan 18, 2024 | Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions ... |
| CVE-2024-22401 | MEDIUM | 4.3 | 0.5% | Jan 18, 2024 | Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions ... |
| CVE-2024-22403 | LOW | 3.7 | 0.5% | Jan 18, 2024 | Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attack... |
| CVE-2024-22400 | MEDIUM | 6.1 | 0.5% | Jan 18, 2024 | Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a l... |
| CVE-2024-22213 | MEDIUM | 5.4 | 0.5% | Jan 18, 2024 | Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with N... |
| CVE-2024-22419 | CRITICAL | 9.8 | 0.8% | Jan 18, 2024 | Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the b... |
| CVE-2024-22212 | CRITICAL | 9.8 | 0.8% | Jan 18, 2024 | Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users t... |
| CVE-2024-0694 | — | — | — | Jan 18, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-6620. Reason: This candidate is a r... |
| CVE-2024-22819 | HIGH | 8.8 | 0.3% | Jan 18, 2024 | FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now