2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0649 | CRITICAL | 9.8 | 0.5% | Jan 17, 2024 | A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download... |
| CVE-2024-0648 | CRITICAL | 9.8 | 0.7% | Jan 17, 2024 | A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown ... |
| CVE-2024-22414 | MEDIUM | 5.4 | 0.4% | Jan 17, 2024 | flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user... |
| CVE-2024-22410 | HIGH | 7.8 | 0.2% | Jan 17, 2024 | Creditcoin is a network that enables cross-blockchain credit transactions. The Windows binary of the Creditcoin node loa... |
| CVE-2024-0647 | MEDIUM | 6.1 | 0.7% | Jan 17, 2024 | A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an un... |
| CVE-2024-22715 | HIGH | 8.8 | 0.3% | Jan 17, 2024 | Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.ph... |
| CVE-2024-22714 | MEDIUM | 6.1 | 0.4% | Jan 17, 2024 | Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content. |
| CVE-2024-20287 | HIGH | 7.2 | 1.4% | Jan 17, 2024 | A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) wit... |
| CVE-2024-20277 | HIGH | 8 | 0.8% | Jan 17, 2024 | A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installa... |
| CVE-2024-20272 | CRITICAL | 9.8 | 1.6% | Jan 17, 2024 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a... |
| CVE-2024-20270 | MEDIUM | 5.4 | 0.4% | Jan 17, 2024 | A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadW... |
| CVE-2024-20251 | MEDIUM | 5.4 | 0.4% | Jan 17, 2024 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat... |
| CVE-2024-0646 | HIGH | 7.8 | 0.3% | Jan 17, 2024 | An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user ... |
| CVE-2024-0641 | MEDIUM | 5.5 | 0.2% | Jan 17, 2024 | A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC su... |
| CVE-2024-0639 | MEDIUM | 5.5 | 0.2% | Jan 17, 2024 | A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux... |
| CVE-2024-0396 | HIGH | 7.1 | 0.5% | Jan 17, 2024 | In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.... |
| CVE-2024-0645 | HIGH | 7.8 | 0.2% | Jan 17, 2024 | Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code v... |
| CVE-2024-0643 | CRITICAL | 9.8 | 0.7% | Jan 17, 2024 | Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerabi... |
| CVE-2024-0642 | CRITICAL | 9.8 | 0.6% | Jan 17, 2024 | Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remo... |
| CVE-2024-0405 | MEDIUM | 6.5 | 0.6% | Jan 17, 2024 | The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticat... |
| CVE-2024-22409 | HIGH | 8.8 | 0.7% | Jan 16, 2024 | DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group ... |
| CVE-2024-22408 | HIGH | 8.1 | 0.4% | Jan 16, 2024 | Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application d... |
| CVE-2024-22407 | MEDIUM | 6.5 | 0.4% | Jan 16, 2024 | Shopware is an open headless commerce platform. In the Shopware CMS, the state handler for orders fails to sufficiently ... |
| CVE-2024-22406 | CRITICAL | 9.8 | 0.6% | Jan 16, 2024 | Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enabl... |
| CVE-2024-22916 | CRITICAL | 9.8 | 1.0% | Jan 16, 2024 | In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now