2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21795 | CRITICAL | 9.8 | 1.8% | Feb 20, 2024 | A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.... |
| CVE-2024-23114 | CRITICAL | 9.8 | 1.1% | Feb 20, 2024 | Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vul... |
| CVE-2024-22824 | CRITICAL | 9.8 | 1.1% | Feb 20, 2024 | An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadC... |
| CVE-2024-25198 | CRITICAL | 9.1 | 0.7% | Feb 20, 2024 | Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robo... |
| CVE-2024-1554 | CRITICAL | 9.8 | 0.4% | Feb 20, 2024 | The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional header... |
| CVE-2024-24794 | CRITICAL | 9.8 | 1.1% | Feb 20, 2024 | A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5... |
| CVE-2024-24793 | CRITICAL | 9.8 | 1.1% | Feb 20, 2024 | A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5... |
| CVE-2024-21896 | CRITICAL | 9.8 | 1.3% | Feb 20, 2024 | The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the ... |
| CVE-2024-0715 | CRITICAL | 9.8 | 0.5% | Feb 20, 2024 | Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue a... |
| CVE-2024-1651 | CRITICAL | 9.8 | 34.0% | Feb 20, 2024 | Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application i... |
| CVE-2024-1638 | CRITICAL | 9.1 | 0.4% | Feb 19, 2024 | The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characte... |
| CVE-2024-25626 | CRITICAL | 9.8 | 1.2% | Feb 19, 2024 | Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless... |
| CVE-2024-25625 | CRITICAL | 9.3 | 0.7% | Feb 19, 2024 | Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered... |
| CVE-2024-1597 | CRITICAL | 9.8 | 4.8% | Feb 19, 2024 | pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the ... |
| CVE-2024-1344 | CRITICAL | 9.8 | 0.3% | Feb 19, 2024 | Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read... |
| CVE-2024-24722 | CRITICAL | 9.1 | 0.6% | Feb 19, 2024 | An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an att... |
| CVE-2024-1512 | CRITICAL | 9.8 | 77.7% | Feb 17, 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union base... |
| CVE-2024-0610 | CRITICAL | 9.8 | 0.7% | Feb 17, 2024 | The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via th... |
| CVE-2024-21495 | CRITICAL | 9.8 | 0.7% | Feb 17, 2024 | Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to us... |
| CVE-2024-25320 | CRITICAL | 9.8 | 0.7% | Feb 16, 2024 | Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /af... |
| CVE-2024-22426 | CRITICAL | 9.8 | 1.4% | Feb 16, 2024 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated... |
| CVE-2024-22425 | CRITICAL | 9.8 | 0.5% | Feb 16, 2024 | Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains a brute force/dictionary attack vulnerability. An unauthe... |
| CVE-2024-24377 | CRITICAL | 9.8 | 1.1% | Feb 16, 2024 | An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information ... |
| CVE-2024-25414 | CRITICAL | 9.8 | 1.6% | Feb 16, 2024 | An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code vi... |
| CVE-2024-0031 | CRITICAL | 9.8 | 0.6% | Feb 16, 2024 | In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now