2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20741 | HIGH | 7.8 | 0.3% | Feb 15, 2024 | Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could r... |
| CVE-2024-20740 | HIGH | 7.8 | 0.2% | Feb 15, 2024 | Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result ... |
| CVE-2024-20723 | HIGH | 7.8 | 0.4% | Feb 15, 2024 | Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in ar... |
| CVE-2024-24386 | HIGH | 7.2 | 1.0% | Feb 15, 2024 | An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalp... |
| CVE-2024-0353 | HIGH | 7.8 | 0.6% | Feb 15, 2024 | Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete file... |
| CVE-2024-1488 | HIGH | 7.3 | 0.3% | Feb 15, 2024 | A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound grou... |
| CVE-2024-26263 | HIGH | 7.5 | 0.4% | Feb 15, 2024 | EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse speci... |
| CVE-2024-26262 | HIGH | 8.8 | 0.8% | Feb 15, 2024 | EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remot... |
| CVE-2024-1523 | HIGH | 8.8 | 0.8% | Feb 15, 2024 | EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authent... |
| CVE-2024-24301 | HIGH | 8.8 | 2.1% | Feb 14, 2024 | Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allo... |
| CVE-2024-1367 | HIGH | 7.2 | 1.6% | Feb 14, 2024 | A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the S... |
| CVE-2024-25618 | HIGH | 7.4 | 0.5% | Feb 14, 2024 | Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configur... |
| CVE-2024-25617 | HIGH | 7.5 | 88.9% | Feb 14, 2024 | Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into ... |
| CVE-2024-25165 | HIGH | 7.8 | 0.5% | Feb 14, 2024 | A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex. |
| CVE-2024-25301 | HIGH | 7.2 | 1.5% | Feb 14, 2024 | Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.... |
| CVE-2024-0008 | HIGH | 8.8 | 0.5% | Feb 14, 2024 | Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, maki... |
| CVE-2024-24990 | HIGH | 7.5 | 0.9% | Feb 14, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p... |
| CVE-2024-24989 | HIGH | 7.5 | 1.1% | Feb 14, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker p... |
| CVE-2024-24775 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traf... |
| CVE-2024-23982 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Tr... |
| CVE-2024-23979 | HIGH | 7.5 | 0.3% | Feb 14, 2024 | When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is co... |
| CVE-2024-23805 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility an... |
| CVE-2024-23314 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management M... |
| CVE-2024-23308 | HIGH | 7.5 | 0.5% | Feb 14, 2024 | When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, un... |
| CVE-2024-23306 | HIGH | 7.1 | 0.2% | Feb 14, 2024 | A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: S... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now