2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3351 | CRITICAL | 9.8 | 0.9% | Apr 5, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Aplaya Beach Resort Online Reservation Sy... |
| CVE-2024-3350 | CRITICAL | 9.8 | 0.9% | Apr 5, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservati... |
| CVE-2024-31849 | CRITICAL | 9.8 | 6.1% | Apr 5, 2024 | A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded J... |
| CVE-2024-31848 | CRITICAL | 9.8 | 8.2% | Apr 5, 2024 | A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedde... |
| CVE-2024-3349 | CRITICAL | 9.8 | 0.9% | Apr 5, 2024 | A vulnerability classified as critical was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Af... |
| CVE-2024-3348 | CRITICAL | 9.8 | 0.9% | Apr 5, 2024 | A vulnerability classified as critical has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.... |
| CVE-2024-3347 | CRITICAL | 9.8 | 0.9% | Apr 5, 2024 | A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This i... |
| CVE-2024-31218 | CRITICAL | 9.8 | 0.7% | Apr 5, 2024 | Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in ... |
| CVE-2024-30849 | CRITICAL | 9.8 | 1.1% | Apr 5, 2024 | Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute ... |
| CVE-2024-27448 | CRITICAL | 9.1 | 0.9% | Apr 5, 2024 | MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading t... |
| CVE-2024-31211 | CRITICAL | 9.8 | 2.7% | Apr 4, 2024 | WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows f... |
| CVE-2024-27981 | CRITICAL | 9.8 | 1.2% | Apr 4, 2024 | A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V... |
| CVE-2024-21894 | CRITICAL | 9.8 | 19.0% | Apr 4, 2024 | A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an... |
| CVE-2024-3315 | CRITICAL | 9.8 | 0.7% | Apr 4, 2024 | A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been classified as critica... |
| CVE-2024-3314 | CRITICAL | 9.8 | 0.5% | Apr 4, 2024 | A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0 and classified as critical. This i... |
| CVE-2024-30264 | CRITICAL | 9.3 | 0.8% | Apr 4, 2024 | Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prio... |
| CVE-2024-28787 | CRITICAL | 10 | 0.8% | Apr 4, 2024 | IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote at... |
| CVE-2024-25693 | CRITICAL | 9.9 | 1.3% | Apr 4, 2024 | There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authe... |
| CVE-2024-3116 | CRITICAL | 9.8 | 64.8% | Apr 4, 2024 | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vu... |
| CVE-2024-29006 | CRITICAL | 9.8 | 0.9% | Apr 4, 2024 | By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an A... |
| CVE-2024-29375 | CRITICAL | 9.8 | 1.5% | Apr 4, 2024 | CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a craf... |
| CVE-2024-2692 | CRITICAL | 9 | 0.7% | Apr 4, 2024 | SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vuln... |
| CVE-2024-3273 | CRITICAL | 9.8 | 100.0% | Apr 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325... |
| CVE-2024-3272 | CRITICAL | 9.8 | 98.0% | Apr 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320... |
| CVE-2024-30568 | CRITICAL | 9.8 | 47.2% | Apr 3, 2024 | Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now