2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25909 | HIGH | 8.8 | 0.6% | Feb 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media ... |
| CVE-2024-24714 | HIGH | 7.2 | 0.6% | Feb 26, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons... |
| CVE-2024-23839 | HIGH | 8.1 | 0.8% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P... |
| CVE-2024-23837 | HIGH | 7.5 | 1.2% | Feb 26, 2024 | LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP hea... |
| CVE-2024-23836 | HIGH | 7.5 | 1.2% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2024-23835 | HIGH | 7.5 | 0.9% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P... |
| CVE-2024-22873 | HIGH | 8.1 | 0.7% | Feb 26, 2024 | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subs... |
| CVE-2024-22371 | HIGH | 7.5 | 0.7% | Feb 26, 2024 | Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that expo... |
| CVE-2024-22201 | HIGH | 7.5 | 1.4% | Feb 26, 2024 | Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will... |
| CVE-2024-1889 | HIGH | 8.8 | 0.3% | Feb 26, 2024 | Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability cou... |
| CVE-2024-1886 | HIGH | 8.8 | 0.8% | Feb 26, 2024 | This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage. |
| CVE-2024-1878 | HIGH | 8.8 | 0.6% | Feb 26, 2024 | A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2024-1877 | HIGH | 8.8 | 0.6% | Feb 26, 2024 | A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected b... |
| CVE-2024-1875 | HIGH | 8.8 | 0.9% | Feb 26, 2024 | A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affec... |
| CVE-2024-1758 | HIGH | 8.1 | 0.5% | Feb 26, 2024 | The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2024-1710 | HIGH | 8.8 | 0.7% | Feb 26, 2024 | The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on... |
| CVE-2024-1622 | HIGH | 7.5 | 1.0% | Feb 26, 2024 | Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too q... |
| CVE-2024-0455 | HIGH | 7.5 | 0.8% | Feb 26, 2024 | The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin... |
| CVE-2024-0439 | HIGH | 8.8 | 0.6% | Feb 26, 2024 | As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience fo... |
| CVE-2024-0243 | HIGH | 8.1 | 0.5% | Feb 26, 2024 | With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" ... |
| CVE-2024-21502 | HIGH | 7.5 | 1.0% | Feb 24, 2024 | Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the cur... |
| CVE-2024-26192 | HIGH | 8.2 | 1.5% | Feb 23, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-25469 | HIGH | 7.5 | 0.8% | Feb 23, 2024 | SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive informat... |
| CVE-2024-24310 | HIGH | 8.8 | 0.5% | Feb 23, 2024 | In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaS... |
| CVE-2024-24309 | HIGH | 7.5 | 0.6% | Feb 23, 2024 | In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download pers... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now