2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25309 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.p... |
| CVE-2024-25308 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.p... |
| CVE-2024-25306 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php". |
| CVE-2024-25305 | HIGH | 8.8 | 0.9% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters a... |
| CVE-2024-25304 | HIGH | 8.8 | 0.7% | Feb 9, 2024 | Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php." |
| CVE-2024-25677 | HIGH | 8.8 | 0.6% | Feb 9, 2024 | In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly ... |
| CVE-2024-23749 | HIGH | 7.8 | 4.7% | Feb 9, 2024 | KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insuffic... |
| CVE-2024-25004 | HIGH | 7.8 | 1.8% | Feb 9, 2024 | KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insuf... |
| CVE-2024-25003 | HIGH | 7.8 | 1.8% | Feb 9, 2024 | KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insuf... |
| CVE-2024-0229 | HIGH | 7.8 | 1.2% | Feb 9, 2024 | An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a... |
| CVE-2024-0842 | HIGH | 7.5 | 1.0% | Feb 9, 2024 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all version... |
| CVE-2024-24819 | HIGH | 8.8 | 0.3% | Feb 9, 2024 | icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class... |
| CVE-2024-23639 | HIGH | 7.8 | 0.3% | Feb 9, 2024 | Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM... |
| CVE-2024-24825 | HIGH | 7.5 | 0.5% | Feb 9, 2024 | DIRAC is a distributed resource framework. In affected versions any user could get a token that has been requested by an... |
| CVE-2024-24821 | HIGH | 7.8 | 0.3% | Feb 9, 2024 | Composer is a dependency Manager for the PHP language. In affected versions several files within the local working direc... |
| CVE-2024-24820 | HIGH | 8.3 | 0.4% | Feb 9, 2024 | Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configurat... |
| CVE-2024-24830 | HIGH | 8.8 | 0.7% | Feb 8, 2024 | OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at pet... |
| CVE-2024-23756 | HIGH | 7.5 | 0.6% | Feb 8, 2024 | The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated... |
| CVE-2024-23660 | HIGH | 7.5 | 0.6% | Feb 8, 2024 | The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezo... |
| CVE-2024-1329 | HIGH | 7.5 | 0.6% | Feb 8, 2024 | HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file wri... |
| CVE-2024-22795 | HIGH | 7 | 0.3% | Feb 8, 2024 | Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privi... |
| CVE-2024-24113 | HIGH | 8.8 | 0.6% | Feb 8, 2024 | xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control ex... |
| CVE-2024-0985 | HIGH | 8 | 1.5% | Feb 8, 2024 | Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrar... |
| CVE-2024-23452 | HIGH | 7.5 | 1.6% | Feb 8, 2024 | Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle re... |
| CVE-2024-25148 | HIGH | 8.1 | 0.5% | Feb 8, 2024 | In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 be... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now