2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20655 | MEDIUM | 6.6 | 1.4% | Jan 9, 2024 | Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability |
| CVE-2024-20654 | HIGH | 8 | 2.0% | Jan 9, 2024 | Microsoft ODBC Driver Remote Code Execution Vulnerability |
| CVE-2024-20653 | HIGH | 7.8 | 4.5% | Jan 9, 2024 | Microsoft Common Log File System Elevation of Privilege Vulnerability |
| CVE-2024-20652 | HIGH | 8.1 | 2.1% | Jan 9, 2024 | Windows HTML Platforms Security Feature Bypass Vulnerability |
| CVE-2024-0340 | MEDIUM | 5.5 | 0.2% | Jan 9, 2024 | A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initial... |
| CVE-2024-0226 | MEDIUM | 5.4 | 0.3% | Jan 9, 2024 | Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a spec... |
| CVE-2024-0057 | CRITICAL | 9.8 | 2.8% | Jan 9, 2024 | NET, .NET Framework, and Visual Studio Security Feature Bypass Vulnerability |
| CVE-2024-0056 | HIGH | 8.7 | 1.2% | Jan 9, 2024 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability |
| CVE-2024-22165 | MEDIUM | 6.5 | 0.5% | Jan 9, 2024 | In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perfor... |
| CVE-2024-22164 | MEDIUM | 4.3 | 0.5% | Jan 9, 2024 | In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a deni... |
| CVE-2024-0228 | — | — | — | Jan 9, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of ... |
| CVE-2024-0213 | HIGH | 7.8 | 0.2% | Jan 9, 2024 | A buffer overflow vulnerability in TA for Linux and TA for MacOS prior to 5.8.1 allows a local user to gain elevated pe... |
| CVE-2024-0206 | HIGH | 7.8 | 0.2% | Jan 9, 2024 | A symbolic link manipulation vulnerability in Trellix Anti-Malware Engine prior to the January 2024 release allows an a... |
| CVE-2024-22370 | MEDIUM | 5.4 | 0.4% | Jan 9, 2024 | In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible |
| CVE-2024-22368 | MEDIUM | 5.5 | 0.5% | Jan 9, 2024 | The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a cra... |
| CVE-2024-22125 | HIGH | 7.5 | 0.5% | Jan 9, 2024 | Under certain conditions the Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) - version 1.0, allo... |
| CVE-2024-22124 | HIGH | 7.5 | 0.3% | Jan 9, 2024 | Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53... |
| CVE-2024-21738 | MEDIUM | 5.4 | 0.3% | Jan 9, 2024 | SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in ... |
| CVE-2024-21737 | CRITICAL | 9.1 | 0.6% | Jan 9, 2024 | In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to tr... |
| CVE-2024-21736 | MEDIUM | 6.5 | 0.3% | Jan 9, 2024 | SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary au... |
| CVE-2024-21735 | HIGH | 7.2 | 0.4% | Jan 9, 2024 | SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not per... |
| CVE-2024-21734 | MEDIUM | 5.4 | 0.2% | Jan 9, 2024 | SAP Marketing (Contacts App) - version 160, allows an attacker with low privileges to trick a user to open malicious pag... |
| CVE-2024-21646 | CRITICAL | 9.8 | 5.1% | Jan 9, 2024 | Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP ... |
| CVE-2024-21663 | HIGH | 8.8 | 1.5% | Jan 9, 2024 | Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a dis... |
| CVE-2024-21651 | MEDIUM | 6.5 | 0.6% | Jan 9, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now