2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25728 | HIGH | 7.5 | 0.7% | Feb 11, 2024 | ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configur... |
| CVE-2024-25419 | HIGH | 8.8 | 0.3% | Feb 11, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_men... |
| CVE-2024-25418 | HIGH | 8.8 | 0.3% | Feb 11, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_men... |
| CVE-2024-25417 | HIGH | 8.8 | 0.3% | Feb 11, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_transl... |
| CVE-2024-22313 | HIGH | 7.8 | 0.1% | Feb 10, 2024 | IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, ... |
| CVE-2024-22361 | HIGH | 7.5 | 0.3% | Feb 10, 2024 | IBM Semeru Runtime 8.0.302.0 through 8.0.392.0, 11.0.12.0 through 11.0.21.0, 17.0.1.0 - 17.0.9.0, and 21.0.1.0 uses weak... |
| CVE-2024-0594 | HIGH | 8.8 | 0.6% | Feb 10, 2024 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injectio... |
| CVE-2024-21490 | HIGH | 7.5 | 1.8% | Feb 10, 2024 | This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular express... |
| CVE-2024-24828 | HIGH | 7.8 | 0.2% | Feb 9, 2024 | pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written t... |
| CVE-2024-23327 | HIGH | 7.5 | 0.7% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, t... |
| CVE-2024-23325 | HIGH | 7.5 | 0.8% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that i... |
| CVE-2024-23324 | HIGH | 7.5 | 0.6% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections... |
| CVE-2024-23322 | HIGH | 7.5 | 0.7% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same int... |
| CVE-2024-1404 | HIGH | 7.5 | 0.8% | Feb 9, 2024 | A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unkno... |
| CVE-2024-25450 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts(). |
| CVE-2024-25448 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow ... |
| CVE-2024-25447 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer ove... |
| CVE-2024-25446 | HIGH | 7.8 | 0.4% | Feb 9, 2024 | An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer over... |
| CVE-2024-25445 | HIGH | 7.8 | 0.3% | Feb 9, 2024 | Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure. |
| CVE-2024-25443 | HIGH | 7.8 | 0.3% | Feb 9, 2024 | An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-... |
| CVE-2024-25442 | HIGH | 7.8 | 0.4% | Feb 9, 2024 | An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap bu... |
| CVE-2024-25318 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2. |
| CVE-2024-25310 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5.... |
| CVE-2024-25313 | HIGH | 8.8 | 0.8% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a... |
| CVE-2024-25312 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now