2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31851 | HIGH | 8.6 | 2.9% | Apr 5, 2024 | A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jett... |
| CVE-2024-31850 | HIGH | 8.6 | 3.0% | Apr 5, 2024 | A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty... |
| CVE-2024-22004 | HIGH | 7.7 | 0.2% | Apr 5, 2024 | Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability... |
| CVE-2024-31220 | HIGH | 7.3 | 0.5% | Apr 5, 2024 | Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an att... |
| CVE-2024-31083 | HIGH | 7.8 | 1.8% | Apr 5, 2024 | A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when A... |
| CVE-2024-26810 | HIGH | 7.8 | 0.2% | Apr 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Lock external INTx masking ops Mask oper... |
| CVE-2024-3217 | HIGH | 8.8 | 1.9% | Apr 5, 2024 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' pa... |
| CVE-2024-30891 | HIGH | 8.8 | 1.9% | Apr 5, 2024 | A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to con... |
| CVE-2024-2115 | HIGH | 8.8 | 0.3% | Apr 5, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2024-29863 | HIGH | 7.8 | 0.4% | Apr 5, 2024 | A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR... |
| CVE-2024-29672 | HIGH | 8.8 | 1.3% | Apr 5, 2024 | Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code v... |
| CVE-2024-22363 | HIGH | 7.5 | 0.8% | Apr 5, 2024 | SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS). |
| CVE-2024-31498 | HIGH | 8.8 | 0.6% | Apr 4, 2024 | Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation b... |
| CVE-2024-31212 | HIGH | 7.2 | 0.9% | Apr 4, 2024 | InstantCMS is a free and open source content management system. A SQL injection vulnerability affects instantcms v2.16.2... |
| CVE-2024-31210 | HIGH | 8.8 | 0.9% | Apr 4, 2024 | WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be sub... |
| CVE-2024-31206 | HIGH | 8.2 | 0.3% | Apr 4, 2024 | dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `dectalk-tts@1.0.0`, network requests to th... |
| CVE-2024-3316 | HIGH | 8.8 | 0.6% | Apr 4, 2024 | A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical.... |
| CVE-2024-3311 | HIGH | 8.8 | 1.0% | Apr 4, 2024 | A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability... |
| CVE-2024-30255 | HIGH | 7.5 | 87.8% | Apr 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. The HTTP/2 protocol stack in Envoy versions prior to 1.29.3... |
| CVE-2024-29387 | HIGH | 8.8 | 1.2% | Apr 4, 2024 | projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/pri... |
| CVE-2024-27316 | HIGH | 7.5 | 91.3% | Apr 4, 2024 | HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP... |
| CVE-2024-22053 | HIGH | 8.2 | 3.5% | Apr 4, 2024 | A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an... |
| CVE-2024-22052 | HIGH | 7.5 | 3.8% | Apr 4, 2024 | A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secur... |
| CVE-2024-30249 | HIGH | 8.6 | 0.6% | Apr 4, 2024 | Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.... |
| CVE-2024-25007 | HIGH | 7.1 | 0.4% | Apr 4, 2024 | Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now