2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24470 | HIGH | 8.8 | 0.5% | Feb 2, 2024 | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-24161 | HIGH | 7.5 | 0.7% | Feb 2, 2024 | MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not fil... |
| CVE-2024-23831 | HIGH | 7.5 | 0.3% | Feb 2, 2024 | LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active sess... |
| CVE-2024-22107 | HIGH | 7.2 | 2.5% | Feb 2, 2024 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/s... |
| CVE-2024-0269 | HIGH | 8.8 | 5.4% | Feb 2, 2024 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary Dril... |
| CVE-2024-0253 | HIGH | 8.8 | 5.0% | Feb 2, 2024 | ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data. |
| CVE-2024-1201 | HIGH | 7.8 | 0.2% | Feb 2, 2024 | Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability co... |
| CVE-2024-0844 | HIGH | 7.2 | 0.7% | Feb 2, 2024 | The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in ... |
| CVE-2024-22851 | HIGH | 7.5 | 1.2% | Feb 2, 2024 | Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information ... |
| CVE-2024-24524 | HIGH | 8.8 | 0.5% | Feb 2, 2024 | Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code... |
| CVE-2024-21860 | HIGH | 8.8 | 0.4% | Feb 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use a... |
| CVE-2024-21851 | HIGH | 7.8 | 0.2% | Feb 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow. |
| CVE-2024-21845 | HIGH | 7.8 | 0.2% | Feb 2, 2024 | in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow. |
| CVE-2024-21780 | HIGH | 7.5 | 0.7% | Feb 2, 2024 | Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted com... |
| CVE-2024-22320 | HIGH | 8.8 | 73.4% | Feb 2, 2024 | IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the sys... |
| CVE-2024-22903 | HIGH | 8.8 | 1.9% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2024-22900 | HIGH | 8.8 | 1.9% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2024-22899 | HIGH | 8.8 | 2.4% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2024-21399 | HIGH | 8.3 | 1.2% | Feb 2, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-22016 | HIGH | 7.8 | 0.2% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada ... |
| CVE-2024-24756 | HIGH | 7.5 | 0.9% | Feb 1, 2024 | Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/`... |
| CVE-2024-21852 | HIGH | 8.8 | 1.2% | Feb 1, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration fi... |
| CVE-2024-0325 | HIGH | 7.8 | 0.8% | Feb 1, 2024 | In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins. |
| CVE-2024-1167 | HIGH | 7.5 | 0.5% | Feb 1, 2024 | When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur. |
| CVE-2024-24557 | HIGH | 7.8 | 0.3% | Feb 1, 2024 | Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now