2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29192 | HIGH | 8.8 | 0.5% | Apr 4, 2024 | gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/... |
| CVE-2024-27268 | HIGH | 7.5 | 1.3% | Apr 4, 2024 | IBM WebSphere Application Server Liberty 18.0.0.2 through 24.0.0.4 is vulnerable to a denial of service, caused by sendi... |
| CVE-2024-25699 | HIGH | 8.5 | 0.7% | Apr 4, 2024 | There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS version... |
| CVE-2024-25695 | HIGH | 7.2 | 0.5% | Apr 4, 2024 | There is a Cross-site Scripting vulnerability in Portal for ArcGIS in versions 11.2 and below that may allow a remote, a... |
| CVE-2024-30263 | HIGH | 7.7 | 0.5% | Apr 4, 2024 | macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF a... |
| CVE-2024-3299 | HIGH | 7.8 | 0.4% | Apr 4, 2024 | Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedur... |
| CVE-2024-3298 | HIGH | 7.8 | 0.3% | Apr 4, 2024 | Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOL... |
| CVE-2024-30250 | HIGH | 7.5 | 0.3% | Apr 4, 2024 | Astro-Shield is an integration to enhance website security with SubResource Integrity hashes, Content-Security-Policy he... |
| CVE-2024-28871 | HIGH | 7.5 | 0.8% | Apr 4, 2024 | LibHTP is a security-aware parser for the HTTP protocol and the related bits and pieces. Version 0.5.46 may parse malfor... |
| CVE-2024-27919 | HIGH | 7.5 | 86.7% | Apr 4, 2024 | Envoy is a cloud-native, open-source edge and service proxy. In versions 1.29.0 and 1.29.1, theEnvoy HTTP/2 protocol sta... |
| CVE-2024-22189 | HIGH | 7.5 | 1.1% | Apr 4, 2024 | quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run ... |
| CVE-2024-31082 | HIGH | 7.3 | 0.3% | Apr 4, 2024 | A heap-based buffer over-read vulnerability was found in the X.org server's ProcAppleDRICreatePixmap() function. This is... |
| CVE-2024-31081 | HIGH | 7.3 | 0.5% | Apr 4, 2024 | A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIPassiveGrabDevice() function. This iss... |
| CVE-2024-31080 | HIGH | 7.3 | 0.5% | Apr 4, 2024 | A heap-based buffer over-read vulnerability was found in the X.org server's ProcXIGetSelectedEvents() function. This iss... |
| CVE-2024-2759 | HIGH | 7.5 | 0.6% | Apr 4, 2024 | Improper access control vulnerability in Apaczka plugin for PrestaShop allows information gathering from saved templates... |
| CVE-2024-2700 | HIGH | 7 | 0.3% | Apr 4, 2024 | A vulnerability was found in the quarkus-core component. Quarkus captures local environment variables from the Quarkus n... |
| CVE-2024-27575 | HIGH | 7.5 | 0.8% | Apr 4, 2024 | INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path ... |
| CVE-2024-26808 | HIGH | 7.8 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_chain_filter: handle NETDEV_UNREGIST... |
| CVE-2024-26804 | HIGH | 7.8 | 0.7% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: ip_tunnel: prevent perpetual headroom growth ... |
| CVE-2024-26800 | HIGH | 7.8 | 0.3% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: tls: fix use-after-free on failed backlog decryptio... |
| CVE-2024-26799 | HIGH | 7 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: ASoC: qcom: Fix uninitialized pointer dmactl In th... |
| CVE-2024-26797 | HIGH | 7.8 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Prevent potential buffer overflow ... |
| CVE-2024-26793 | HIGH | 7.8 | 0.3% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: gtp: fix use-after-free and null-ptr-deref in gtp_n... |
| CVE-2024-26792 | HIGH | 7.8 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of anonymous device after sn... |
| CVE-2024-26791 | HIGH | 7.1 | 0.2% | Apr 4, 2024 | In the Linux kernel, the following vulnerability has been resolved: btrfs: dev-replace: properly validate device names ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now