2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1714 | HIGH | 7.1 | 0.3% | Feb 21, 2024 | An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value... |
| CVE-2024-1708 | HIGH | 8.4 | 87.6% | Feb 21, 2024 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker t... |
| CVE-2024-26582 | HIGH | 7.8 | 0.3% | Feb 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and... |
| CVE-2024-22778 | HIGH | 7.5 | 0.7% | Feb 21, 2024 | HackMD CodiMD <2.5.2 is vulnerable to Denial of Service. |
| CVE-2024-24802 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in John Tendik JTRT Responsive Tables.This issue affects JTRT Responsive... |
| CVE-2024-24798 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in SoniNow Team Debug.This issue affects Debug: from n/a through 1.10. |
| CVE-2024-25904 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and S... |
| CVE-2024-24876 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: f... |
| CVE-2024-24872 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a ... |
| CVE-2024-24849 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects ... |
| CVE-2024-24843 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue... |
| CVE-2024-1675 | HIGH | 8.8 | 10.4% | Feb 21, 2024 | Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass ... |
| CVE-2024-1674 | HIGH | 8.8 | 0.8% | Feb 21, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass n... |
| CVE-2024-1673 | HIGH | 8.8 | 0.8% | Feb 21, 2024 | Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised th... |
| CVE-2024-1670 | HIGH | 8.8 | 9.0% | Feb 21, 2024 | Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-1669 | HIGH | 8.8 | 1.0% | Feb 21, 2024 | Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of... |
| CVE-2024-1108 | HIGH | 8.2 | 0.5% | Feb 21, 2024 | The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2024-23758 | HIGH | 7.5 | 0.5% | Feb 20, 2024 | An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise Manage... |
| CVE-2024-26136 | HIGH | 7.5 | 0.5% | Feb 20, 2024 | kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an accou... |
| CVE-2024-23830 | HIGH | 8.3 | 1.0% | Feb 20, 2024 | MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email ... |
| CVE-2024-26135 | HIGH | 8.8 | 0.5% | Feb 20, 2024 | MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vu... |
| CVE-2024-24474 | HIGH | 8.8 | 1.4% | Feb 20, 2024 | QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA tra... |
| CVE-2024-22250 | HIGH | 7.8 | 0.3% | Feb 20, 2024 | Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unp... |
| CVE-2024-22054 | HIGH | 7.5 | 0.5% | Feb 20, 2024 | A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functi... |
| CVE-2024-21682 | HIGH | 7.2 | 0.8% | Feb 20, 2024 | This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Disco... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now