2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26470 | HIGH | 8.1 | 1.0% | Feb 29, 2024 | A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v... |
| CVE-2024-26461 | HIGH | 7.5 | 1.1% | Feb 29, 2024 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| CVE-2024-26131 | HIGH | 7.8 | 0.5% | Feb 29, 2024 | Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redire... |
| CVE-2024-25932 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows C... |
| CVE-2024-25931 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.... |
| CVE-2024-25930 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Cu... |
| CVE-2024-25832 | HIGH | 8.8 | 12.8% | Feb 29, 2024 | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to ... |
| CVE-2024-25713 | HIGH | 8.6 | 1.8% | Feb 29, 2024 | yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function l... |
| CVE-2024-25262 | HIGH | 8.1 | 0.9% | Feb 29, 2024 | texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulne... |
| CVE-2024-25006 | HIGH | 8.1 | 1.0% | Feb 29, 2024 | XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to adm... |
| CVE-2024-24701 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-base... |
| CVE-2024-23519 | HIGH | 8.8 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before ... |
| CVE-2024-23302 | HIGH | 7.5 | 0.7% | Feb 29, 2024 | Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. |
| CVE-2024-22939 | HIGH | 8.8 | 0.7% | Feb 29, 2024 | Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the syst... |
| CVE-2024-20321 | HIGH | 8.6 | 0.7% | Feb 29, 2024 | A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an una... |
| CVE-2024-20267 | HIGH | 8.6 | 0.9% | Feb 29, 2024 | A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attack... |
| CVE-2024-1939 | HIGH | 8.8 | 2.6% | Feb 29, 2024 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-1938 | HIGH | 8.8 | 0.8% | Feb 29, 2024 | Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object cor... |
| CVE-2024-1928 | HIGH | 7.2 | 0.7% | Feb 29, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-Based Student Clearance System 1... |
| CVE-2024-1470 | HIGH | 7.8 | 0.2% | Feb 29, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows all... |
| CVE-2024-1317 | HIGH | 8.8 | 0.7% | Feb 29, 2024 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2024-1206 | HIGH | 8.8 | 0.7% | Feb 29, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up t... |
| CVE-2024-0702 | HIGH | 7.3 | 0.5% | Feb 29, 2024 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to miss... |
| CVE-2024-26146 | HIGH | 7.5 | 2.0% | Feb 29, 2024 | Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer t... |
| CVE-2024-26141 | HIGH | 7.5 | 1.6% | Feb 29, 2024 | Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexp... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now