2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1222 | CRITICAL | 9.8 | 64.0% | Mar 14, 2024 | This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated... |
| CVE-2024-25250 | CRITICAL | 9.8 | 0.6% | Mar 13, 2024 | SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code vi... |
| CVE-2024-28194 | CRITICAL | 9.8 | 0.8% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSO... |
| CVE-2024-0799 | CRITICAL | 9.8 | 4.3% | Mar 13, 2024 | An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui... |
| CVE-2024-2418 | CRITICAL | 9.8 | 0.7% | Mar 13, 2024 | A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been declared as critical. Affected b... |
| CVE-2024-2172 | CRITICAL | 9.8 | 1.7% | Mar 13, 2024 | The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to ... |
| CVE-2024-1071 | CRITICAL | 9.8 | 89.4% | Mar 13, 2024 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi... |
| CVE-2024-25153 | CRITICAL | 9.8 | 41.7% | Mar 13, 2024 | A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outsid... |
| CVE-2024-2413 | CRITICAL | 9.8 | 0.6% | Mar 13, 2024 | Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string... |
| CVE-2024-24101 | CRITICAL | 9.8 | 0.3% | Mar 12, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update. |
| CVE-2024-2406 | CRITICAL | 9.8 | 0.6% | Mar 12, 2024 | A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index... |
| CVE-2024-24093 | CRITICAL | 9.8 | 0.6% | Mar 12, 2024 | SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Per... |
| CVE-2024-28114 | CRITICAL | 9.1 | 1.3% | Mar 12, 2024 | Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to ... |
| CVE-2024-27317 | CRITICAL | 9.9 | 56.9% | Mar 12, 2024 | In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip f... |
| CVE-2024-27135 | CRITICAL | 9.9 | 6.0% | Mar 12, 2024 | Improper input validation in the Pulsar Function Worker allows a malicious authenticated user to execute arbitrary Java ... |
| CVE-2024-21400 | CRITICAL | 9 | 2.2% | Mar 12, 2024 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability |
| CVE-2024-21334 | CRITICAL | 9.8 | 20.2% | Mar 12, 2024 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability |
| CVE-2024-2394 | CRITICAL | 9.8 | 0.6% | Mar 12, 2024 | A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-2393 | CRITICAL | 9.8 | 0.7% | Mar 12, 2024 | A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by ... |
| CVE-2024-28553 | CRITICAL | 9.8 | 0.8% | Mar 12, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function. |
| CVE-2024-28535 | CRITICAL | 9.8 | 0.8% | Mar 12, 2024 | Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function. |
| CVE-2024-22039 | CRITICAL | 9.8 | 0.8% | Mar 12, 2024 | A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel... |
| CVE-2024-26001 | CRITICAL | 9.8 | 0.9% | Mar 12, 2024 | An unauthenticated remote attacker can write memory out of bounds due to improper input validation in the MQTT stack. Th... |
| CVE-2024-25996 | CRITICAL | 9.8 | 0.4% | Mar 12, 2024 | An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is ... |
| CVE-2024-25995 | CRITICAL | 9.8 | 1.4% | Mar 12, 2024 | An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or per... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now