2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2805 | HIGH | 8.8 | 1.6% | Mar 22, 2024 | A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issu... |
| CVE-2024-29031 | HIGH | 7.5 | 1.0% | Mar 21, 2024 | Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructur... |
| CVE-2024-28171 | HIGH | 8.1 | 0.6% | Mar 21, 2024 | It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specif... |
| CVE-2024-28040 | HIGH | 8.8 | 8.5% | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_astListParameters. |
| CVE-2024-25567 | HIGH | 8.8 | 0.7% | Mar 21, 2024 | Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If ... |
| CVE-2024-23975 | HIGH | 8.8 | 8.5% | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_slogListParameters. |
| CVE-2024-23494 | HIGH | 8.8 | 8.5% | Mar 21, 2024 | SQL injection vulnerability exists in GetDIAE_unListParameters. |
| CVE-2024-28891 | HIGH | 8.8 | 8.5% | Mar 21, 2024 | SQL injection vulnerability exists in the script Handler_CFG.ashx. |
| CVE-2024-28521 | HIGH | 7.8 | 0.3% | Mar 21, 2024 | SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute ar... |
| CVE-2024-28119 | HIGH | 8.8 | 1.6% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ... |
| CVE-2024-28118 | HIGH | 8.8 | 1.2% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ... |
| CVE-2024-28117 | HIGH | 8.8 | 1.4% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible function... |
| CVE-2024-28116 | HIGH | 8.8 | 5.8% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-... |
| CVE-2024-28029 | HIGH | 8.8 | 0.7% | Mar 21, 2024 | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authoriza... |
| CVE-2024-27921 | HIGH | 8.8 | 60.6% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identif... |
| CVE-2024-25937 | HIGH | 8.8 | 8.5% | Mar 21, 2024 | SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. |
| CVE-2024-24272 | HIGH | 7.1 | 0.2% | Mar 21, 2024 | An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive inf... |
| CVE-2024-2764 | HIGH | 8.8 | 1.5% | Mar 21, 2024 | A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formS... |
| CVE-2024-2763 | HIGH | 8.8 | 1.5% | Mar 21, 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is ... |
| CVE-2024-29180 | HIGH | 7.5 | 1.2% | Mar 21, 2024 | Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not valida... |
| CVE-2024-27964 | HIGH | 8.8 | 0.6% | Mar 21, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: ... |
| CVE-2024-27190 | HIGH | 8.8 | 0.4% | Mar 21, 2024 | Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a thro... |
| CVE-2024-2465 | HIGH | 7.1 | 0.5% | Mar 21, 2024 | Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafte... |
| CVE-2024-2463 | HIGH | 8 | 0.6% | Mar 21, 2024 | Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX app... |
| CVE-2024-27994 | HIGH | 7.1 | 0.4% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooC... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now