2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22567 | HIGH | 8.8 | 17.8% | Feb 5, 2024 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/... |
| CVE-2024-24267 | HIGH | 7.5 | 1.6% | Feb 5, 2024 | gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_b... |
| CVE-2024-24266 | HIGH | 7.5 | 1.3% | Feb 5, 2024 | gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src... |
| CVE-2024-24265 | HIGH | 7.5 | 1.3% | Feb 5, 2024 | gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_int... |
| CVE-2024-24263 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_lin... |
| CVE-2024-24262 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function a... |
| CVE-2024-24260 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function... |
| CVE-2024-24259 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry functi... |
| CVE-2024-24258 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. |
| CVE-2024-24469 | HIGH | 8.8 | 0.5% | Feb 5, 2024 | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-24468 | HIGH | 8.8 | 0.5% | Feb 5, 2024 | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-24768 | HIGH | 7.5 | 0.3% | Feb 5, 2024 | 1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the p... |
| CVE-2024-24762 | HIGH | 7.5 | 1.5% | Feb 5, 2024 | `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular E... |
| CVE-2024-22667 | HIGH | 7.8 | 0.6% | Feb 5, 2024 | Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the err... |
| CVE-2024-20015 | HIGH | 7.8 | 0.1% | Feb 5, 2024 | In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalati... |
| CVE-2024-20009 | HIGH | 8.8 | 0.4% | Feb 5, 2024 | In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote e... |
| CVE-2024-20007 | HIGH | 7.5 | 0.3% | Feb 5, 2024 | In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of... |
| CVE-2024-20004 | HIGH | 7.5 | 1.2% | Feb 5, 2024 | In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of ... |
| CVE-2024-20003 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of ... |
| CVE-2024-25062 | HIGH | 7.5 | 1.4% | Feb 4, 2024 | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD ... |
| CVE-2024-1064 | HIGH | 7.5 | 0.8% | Feb 3, 2024 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticate... |
| CVE-2024-0909 | HIGH | 7.5 | 0.6% | Feb 3, 2024 | The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and... |
| CVE-2024-1199 | HIGH | 7.5 | 0.7% | Feb 3, 2024 | A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected ... |
| CVE-2024-1189 | HIGH | 7.5 | 0.7% | Feb 2, 2024 | A vulnerability has been found in AMPPS 2.7 and classified as problematic. Affected by this vulnerability is an unknown ... |
| CVE-2024-24760 | HIGH | 7.3 | 0.9% | Feb 2, 2024 | mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now