2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1255 | HIGH | 7.5 | 0.6% | Feb 6, 2024 | A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerab... |
| CVE-2024-1254 | HIGH | 7.2 | 4.6% | Feb 6, 2024 | A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. Thi... |
| CVE-2024-1253 | HIGH | 7.2 | 1.7% | Feb 6, 2024 | A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126... |
| CVE-2024-24593 | HIGH | 8.8 | 0.4% | Feb 6, 2024 | A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI... |
| CVE-2024-24591 | HIGH | 8.8 | 0.8% | Feb 6, 2024 | A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AI’s ClearML platform enables a ... |
| CVE-2024-24590 | HIGH | 8.8 | 2.5% | Feb 6, 2024 | Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platf... |
| CVE-2024-23673 | HIGH | 7.5 | 1.3% | Feb 6, 2024 | Malicious code execution via path traversal in Apache Software Foundation Apache Sling Servlets Resolver.This issue affe... |
| CVE-2024-23304 | HIGH | 7.5 | 0.8% | Feb 6, 2024 | Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) co... |
| CVE-2024-20820 | HIGH | 7.1 | 0.2% | Feb 6, 2024 | Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Ou... |
| CVE-2024-20819 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local at... |
| CVE-2024-20818 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attac... |
| CVE-2024-20817 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attac... |
| CVE-2024-20813 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arb... |
| CVE-2024-20812 | HIGH | 7.8 | 0.2% | Feb 6, 2024 | Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arb... |
| CVE-2024-22773 | HIGH | 8.1 | 1.0% | Feb 6, 2024 | Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in C... |
| CVE-2024-24595 | HIGH | 7.1 | 0.3% | Feb 5, 2024 | Allegro AI’s open-source version of ClearML stores passwords in plaintext within the MongoDB instance, resulting in a co... |
| CVE-2024-1072 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | The Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode plugin for Wor... |
| CVE-2024-0761 | HIGH | 7.5 | 1.0% | Feb 5, 2024 | The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-0709 | HIGH | 7.5 | 0.9% | Feb 5, 2024 | The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coin... |
| CVE-2024-0699 | HIGH | 7.2 | 1.2% | Feb 5, 2024 | The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file up... |
| CVE-2024-0668 | HIGH | 7.2 | 1.1% | Feb 5, 2024 | The Advanced Database Cleaner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and incl... |
| CVE-2024-0428 | HIGH | 8.8 | 0.3% | Feb 5, 2024 | The Index Now plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6... |
| CVE-2024-0324 | HIGH | 7.5 | 2.4% | Feb 5, 2024 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2024-0221 | HIGH | 7.2 | 1.3% | Feb 5, 2024 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in ... |
| CVE-2024-1052 | HIGH | 8 | 0.3% | Feb 5, 2024 | Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now