2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25635 | HIGH | 8.8 | 0.7% | Feb 19, 2024 | alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the gener... |
| CVE-2024-25982 | HIGH | 8.8 | 0.5% | Feb 19, 2024 | The link to update all installed language packs did not include the necessary token to prevent a CSRF risk. |
| CVE-2024-25978 | HIGH | 7.5 | 0.9% | Feb 19, 2024 | Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality. |
| CVE-2024-25623 | HIGH | 7.7 | 0.5% | Feb 19, 2024 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and... |
| CVE-2024-1580 | HIGH | 8.8 | 1.8% | Feb 19, 2024 | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to mem... |
| CVE-2024-25468 | HIGH | 7.5 | 0.9% | Feb 17, 2024 | An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_t... |
| CVE-2024-25298 | HIGH | 7.2 | 1.1% | Feb 17, 2024 | An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive inform... |
| CVE-2024-21492 | HIGH | 8.1 | 0.7% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to ... |
| CVE-2024-22727 | HIGH | 8.3 | 0.3% | Feb 17, 2024 | Teltonika TRB1-series devices with firmware before TRB1_R_00.07.05.2 allow attackers to exploit a firmware vulnerability... |
| CVE-2024-20956 | HIGH | 7.3 | 0.4% | Feb 17, 2024 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: In... |
| CVE-2024-20953 | HIGH | 8.8 | 3.4% | Feb 17, 2024 | Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that i... |
| CVE-2024-20931 | HIGH | 7.5 | 59.7% | Feb 17, 2024 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2024-20927 | HIGH | 8.6 | 0.5% | Feb 17, 2024 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2024-20917 | HIGH | 7.5 | 0.4% | Feb 17, 2024 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Log Manage... |
| CVE-2024-20909 | HIGH | 7.5 | 0.4% | Feb 17, 2024 | Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected a... |
| CVE-2024-25628 | HIGH | 7.6 | 0.4% | Feb 16, 2024 | Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access t... |
| CVE-2024-25083 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low-privileged user initiat... |
| CVE-2024-0023 | HIGH | 7.8 | 0.4% | Feb 16, 2024 | In ConvertRGBToPlanarYUV of Codec2BufferUtils.cpp, there is a possible out of bounds write due to an incorrect bounds ch... |
| CVE-2024-0021 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way for an app in the work profile to en... |
| CVE-2024-0018 | HIGH | 7.8 | 0.1% | Feb 16, 2024 | In convertYUV420Planar16ToY410 of ColorConverter.cpp, there is a possible out of bounds write due to a heap buffer overf... |
| CVE-2024-21915 | HIGH | 8.8 | 1.0% | Feb 16, 2024 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, ... |
| CVE-2024-0015 | HIGH | 7.8 | 0.4% | Feb 16, 2024 | In convertToComponentName of DreamService.java, there is a possible way to launch arbitrary protected activities due to ... |
| CVE-2024-21775 | HIGH | 8.8 | 5.0% | Feb 16, 2024 | Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in re... |
| CVE-2024-25466 | HIGH | 7.8 | 0.5% | Feb 16, 2024 | Directory Traversal vulnerability in React Native Document Picker before v.9.1.1 and fixed in v.9.1.1 allows a local att... |
| CVE-2024-25415 | HIGH | 7.2 | 27.2% | Feb 16, 2024 | A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to ex... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now