2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27915 | HIGH | 8.1 | 0.4% | Mar 6, 2024 | Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to page... |
| CVE-2024-2176 | HIGH | 8.8 | 1.3% | Mar 6, 2024 | Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-2174 | HIGH | 8.8 | 12.6% | Mar 6, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exp... |
| CVE-2024-2173 | HIGH | 8.8 | 13.6% | Mar 6, 2024 | Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of b... |
| CVE-2024-27303 | HIGH | 7.3 | 0.3% | Mar 6, 2024 | electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Wind... |
| CVE-2024-27289 | HIGH | 8.1 | 0.9% | Mar 6, 2024 | pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the followin... |
| CVE-2024-27287 | HIGH | 8.7 | 0.7% | Mar 6, 2024 | ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior t... |
| CVE-2024-25111 | HIGH | 7.5 | 65.3% | Mar 6, 2024 | Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of ... |
| CVE-2024-24766 | HIGH | 7.5 | 0.8% | Mar 6, 2024 | CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version ... |
| CVE-2024-24761 | HIGH | 7.5 | 0.6% | Mar 6, 2024 | Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to ... |
| CVE-2024-2216 | HIGH | 8.8 | 0.8% | Mar 6, 2024 | A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers wit... |
| CVE-2024-28160 | HIGH | 8.8 | 1.1% | Mar 6, 2024 | Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored ... |
| CVE-2024-28157 | HIGH | 8 | 1.1% | Mar 6, 2024 | Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-si... |
| CVE-2024-20338 | HIGH | 7.3 | 0.9% | Mar 6, 2024 | A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, l... |
| CVE-2024-20337 | HIGH | 8.2 | 29.9% | Mar 6, 2024 | A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacke... |
| CVE-2024-2005 | HIGH | 8 | 0.5% | Mar 6, 2024 | In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation.... |
| CVE-2024-25102 | HIGH | 7.8 | 0.1% | Mar 6, 2024 | This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user... |
| CVE-2024-1224 | HIGH | 7.1 | 0.1% | Mar 6, 2024 | This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user logi... |
| CVE-2024-26625 | HIGH | 7.8 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot rep... |
| CVE-2024-1220 | HIGH | 7.5 | 0.7% | Mar 6, 2024 | A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and pri... |
| CVE-2024-25817 | HIGH | 7.8 | 0.3% | Mar 6, 2024 | Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .gi... |
| CVE-2024-22889 | HIGH | 7.5 | 0.7% | Mar 6, 2024 | Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the webs... |
| CVE-2024-27765 | HIGH | 7.5 | 0.9% | Mar 5, 2024 | Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information vi... |
| CVE-2024-24786 | HIGH | 7.5 | 1.3% | Mar 5, 2024 | The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condit... |
| CVE-2024-24784 | HIGH | 7.5 | 1.0% | Mar 5, 2024 | The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now