2024 CVE Vulnerabilities
39,219 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24398 | CRITICAL | 9.8 | 2.3% | Feb 6, 2024 | Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker ... |
| CVE-2024-23049 | CRITICAL | 9.8 | 1.2% | Feb 5, 2024 | An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. |
| CVE-2024-0964 | CRITICAL | 9.4 | 1.0% | Feb 5, 2024 | A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API reques... |
| CVE-2024-24543 | CRITICAL | 9.8 | 1.0% | Feb 5, 2024 | Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allo... |
| CVE-2024-23054 | CRITICAL | 9.8 | 1.7% | Feb 5, 2024 | An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution du... |
| CVE-2024-0323 | CRITICAL | 9.8 | 0.2% | Feb 5, 2024 | The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TL... |
| CVE-2024-23109 | CRITICAL | 9.8 | 3.2% | Feb 5, 2024 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2024-23108 | CRITICAL | 9.8 | 78.4% | Feb 5, 2024 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ... |
| CVE-2024-1225 | CRITICAL | 9.8 | 0.9% | Feb 5, 2024 | A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is t... |
| CVE-2024-20011 | CRITICAL | 9.8 | 0.5% | Feb 5, 2024 | In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote ... |
| CVE-2024-25089 | CRITICAL | 9.8 | 1.8% | Feb 4, 2024 | Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC... |
| CVE-2024-1198 | CRITICAL | 9.8 | 0.7% | Feb 3, 2024 | A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi o... |
| CVE-2024-1197 | CRITICAL | 9.8 | 0.6% | Feb 2, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This i... |
| CVE-2024-24757 | CRITICAL | 9.8 | 0.5% | Feb 2, 2024 | open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally... |
| CVE-2024-24029 | CRITICAL | 9.8 | 0.8% | Feb 2, 2024 | JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data. |
| CVE-2024-22108 | CRITICAL | 9.8 | 0.8% | Feb 2, 2024 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureAp... |
| CVE-2024-0338 | CRITICAL | 9.8 | 0.5% | Feb 2, 2024 | A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute a... |
| CVE-2024-23978 | CRITICAL | 9.8 | 0.7% | Feb 2, 2024 | Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbit... |
| CVE-2024-24482 | CRITICAL | 9.8 | 1.2% | Feb 2, 2024 | Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal. |
| CVE-2024-0685 | CRITICAL | 9.8 | 0.8% | Feb 2, 2024 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second... |
| CVE-2024-22533 | CRITICAL | 9.8 | 1.0% | Feb 2, 2024 | Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incomi... |
| CVE-2024-22319 | CRITICAL | 9.8 | 76.4% | Feb 2, 2024 | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remo... |
| CVE-2024-23746 | CRITICAL | 9.8 | 1.3% | Feb 2, 2024 | Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in ... |
| CVE-2024-22902 | CRITICAL | 9.8 | 1.1% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. |
| CVE-2024-22901 | CRITICAL | 9.8 | 1.1% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now