2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25126 | HIGH | 7.5 | 35.4% | Feb 29, 2024 | Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser t... |
| CVE-2024-23910 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote... |
| CVE-2024-25869 | HIGH | 8.8 | 18.7% | Feb 28, 2024 | An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacke... |
| CVE-2024-25866 | HIGH | 8.8 | 0.8% | Feb 28, 2024 | A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute... |
| CVE-2024-22983 | HIGH | 8.1 | 0.9% | Feb 28, 2024 | SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate... |
| CVE-2024-25859 | HIGH | 7.1 | 0.3% | Feb 28, 2024 | A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover u... |
| CVE-2024-24148 | HIGH | 7.5 | 0.6% | Feb 28, 2024 | A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service... |
| CVE-2024-27948 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through ... |
| CVE-2024-26342 | HIGH | 7.5 | 0.9% | Feb 28, 2024 | A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via ... |
| CVE-2024-1847 | HIGH | 7.8 | 0.3% | Feb 28, 2024 | Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Typ... |
| CVE-2024-21749 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all:... |
| CVE-2024-24702 | HIGH | 8.8 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Rest... |
| CVE-2024-27515 | HIGH | 7.2 | 0.6% | Feb 28, 2024 | Osclass 5.1.2 is vulnerable to SQL Injection. |
| CVE-2024-25902 | HIGH | 7.2 | 0.5% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware... |
| CVE-2024-24868 | HIGH | 8.8 | 0.5% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro... |
| CVE-2024-21886 | HIGH | 7.8 | 1.4% | Feb 28, 2024 | A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an appli... |
| CVE-2024-21885 | HIGH | 7.8 | 1.4% | Feb 28, 2024 | A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated arr... |
| CVE-2024-1514 | HIGH | 7.5 | 0.7% | Feb 28, 2024 | The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter ... |
| CVE-2024-26298 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-26297 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-26296 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-26295 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-26294 | HIGH | 8.8 | 0.9% | Feb 27, 2024 | Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a... |
| CVE-2024-0763 | HIGH | 8.1 | 0.9% | Feb 27, 2024 | Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path t... |
| CVE-2024-24027 | HIGH | 7.2 | 0.7% | Feb 27, 2024 | SQL Injection vulnerability in Likeshop before 2.5.7 allows attackers to run abitrary SQL commands via the function Dist... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now