2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24278 | HIGH | 7.5 | 0.7% | Mar 5, 2024 | An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive informa... |
| CVE-2024-1764 | HIGH | 7.6 | 0.4% | Mar 5, 2024 | Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allow... |
| CVE-2024-25858 | HIGH | 8.4 | 0.2% | Mar 5, 2024 | In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an ... |
| CVE-2024-25613 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-25612 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-25611 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-1356 | HIGH | 7.2 | 1.2% | Mar 5, 2024 | Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of ... |
| CVE-2024-23296 | HIGH | 7.8 | 1.4% | Mar 5, 2024 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, i... |
| CVE-2024-23225 | HIGH | 7.8 | 1.5% | Mar 5, 2024 | A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, i... |
| CVE-2024-22255 | HIGH | 7.1 | 2.3% | Mar 5, 2024 | VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malic... |
| CVE-2024-22254 | HIGH | 8.2 | 0.5% | Mar 5, 2024 | VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may ... |
| CVE-2024-27929 | HIGH | 7.1 | 0.4% | Mar 5, 2024 | ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's Initi... |
| CVE-2024-27561 | HIGH | 8.1 | 0.6% | Mar 5, 2024 | A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers... |
| CVE-2024-24098 | HIGH | 7.8 | 0.4% | Mar 5, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed. |
| CVE-2024-27622 | HIGH | 7.2 | 2.0% | Mar 5, 2024 | A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2... |
| CVE-2024-20838 | HIGH | 7.8 | 0.2% | Mar 5, 2024 | Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitr... |
| CVE-2024-20835 | HIGH | 7.8 | 0.1% | Mar 5, 2024 | Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local atta... |
| CVE-2024-22188 | HIGH | 7.2 | 2.0% | Mar 5, 2024 | TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell co... |
| CVE-2024-1731 | HIGH | 8.8 | 0.9% | Mar 5, 2024 | The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inclu... |
| CVE-2024-0825 | HIGH | 8.8 | 0.9% | Mar 5, 2024 | The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all ... |
| CVE-2024-25269 | HIGH | 7.5 | 0.7% | Mar 5, 2024 | libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a de... |
| CVE-2024-27718 | HIGH | 7.8 | 1.1% | Mar 5, 2024 | SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain s... |
| CVE-2024-25731 | HIGH | 7.5 | 0.5% | Mar 5, 2024 | The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can ... |
| CVE-2024-25164 | HIGH | 7.5 | 0.9% | Mar 5, 2024 | iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files... |
| CVE-2024-1936 | HIGH | 7.5 | 0.7% | Mar 4, 2024 | The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email mess... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now