2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1882 | HIGH | 7.2 | 1.4% | Mar 14, 2024 | This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for ... |
| CVE-2024-25652 | HIGH | 8.4 | 0.6% | Mar 14, 2024 | In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access... |
| CVE-2024-1654 | HIGH | 7.2 | 1.3% | Mar 14, 2024 | This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker... |
| CVE-2024-25228 | HIGH | 8.8 | 25.9% | Mar 14, 2024 | Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerify... |
| CVE-2024-28251 | HIGH | 7.3 | 0.2% | Mar 14, 2024 | Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's da... |
| CVE-2024-27102 | HIGH | 8.5 | 0.5% | Mar 13, 2024 | Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions... |
| CVE-2024-24105 | HIGH | 7.8 | 0.3% | Mar 13, 2024 | SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary co... |
| CVE-2024-22167 | HIGH | 7.9 | 0.2% | Mar 13, 2024 | A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrar... |
| CVE-2024-0801 | HIGH | 7.5 | 41.8% | Mar 13, 2024 | A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll. |
| CVE-2024-0800 | HIGH | 8.8 | 1.0% | Mar 13, 2024 | A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.... |
| CVE-2024-2432 | HIGH | 7 | 0.4% | Mar 13, 2024 | A privilege escalation (PE) vulnerability in the Palo Alto Networks GlobalProtect app on Windows devices enables a local... |
| CVE-2024-28195 | HIGH | 8.8 | 0.4% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the ... |
| CVE-2024-20327 | HIGH | 7.4 | 0.3% | Mar 13, 2024 | A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series ... |
| CVE-2024-20320 | HIGH | 7.8 | 0.2% | Mar 13, 2024 | A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Conve... |
| CVE-2024-20318 | HIGH | 7.4 | 0.3% | Mar 13, 2024 | A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attac... |
| CVE-2024-0162 | HIGH | 8.8 | 0.2% | Mar 13, 2024 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulner... |
| CVE-2024-2194 | HIGH | 7.2 | 67.7% | Mar 13, 2024 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all ... |
| CVE-2024-2106 | HIGH | 7.5 | 0.8% | Mar 13, 2024 | The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Informatio... |
| CVE-2024-2006 | HIGH | 8.8 | 1.2% | Mar 13, 2024 | The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is v... |
| CVE-2024-28673 | HIGH | 8.8 | 0.4% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php. |
| CVE-2024-28671 | HIGH | 8.8 | 0.9% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php. |
| CVE-2024-26630 | HIGH | 7.1 | 0.3% | Mar 13, 2024 | In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache w... |
| CVE-2024-24549 | HIGH | 7.5 | 23.1% | Mar 13, 2024 | Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing a... |
| CVE-2024-1951 | HIGH | 7.5 | 1.0% | Mar 13, 2024 | The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Inj... |
| CVE-2024-1950 | HIGH | 8.8 | 1.2% | Mar 13, 2024 | The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now