2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23775 | HIGH | 7.5 | 1.1% | Jan 31, 2024 | Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of... |
| CVE-2024-1069 | HIGH | 7.2 | 1.2% | Jan 31, 2024 | The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validatio... |
| CVE-2024-1077 | HIGH | 8.8 | 0.9% | Jan 30, 2024 | Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap... |
| CVE-2024-1060 | HIGH | 8.8 | 0.9% | Jan 30, 2024 | Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap ... |
| CVE-2024-1059 | HIGH | 8.8 | 0.9% | Jan 30, 2024 | Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially expl... |
| CVE-2024-23838 | HIGH | 7.5 | 0.5% | Jan 30, 2024 | TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain con... |
| CVE-2024-23647 | HIGH | 8.8 | 0.5% | Jan 30, 2024 | Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to c... |
| CVE-2024-21649 | HIGH | 8.8 | 1.3% | Jan 30, 2024 | The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Mul... |
| CVE-2024-1019 | HIGH | 8.6 | 0.7% | Jan 30, 2024 | ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially... |
| CVE-2024-1033 | HIGH | 7.5 | 0.6% | Jan 30, 2024 | A vulnerability, which was classified as problematic, has been found in openBI up to 1.0.8. Affected by this issue is th... |
| CVE-2024-0676 | HIGH | 7.1 | 0.1% | Jan 30, 2024 | Weak password requirement vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version , which allows a lo... |
| CVE-2024-0674 | HIGH | 7.8 | 0.1% | Jan 30, 2024 | Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local ... |
| CVE-2024-1063 | HIGH | 7.5 | 0.4% | Jan 30, 2024 | Appwrite <= v1.4.13 is affected by a Server-Side Request Forgery (SSRF) via the '/v1/avatars/favicon' endpoint due to an... |
| CVE-2024-22523 | HIGH | 7.5 | 1.1% | Jan 30, 2024 | Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive... |
| CVE-2024-21803 | HIGH | 7.8 | 0.5% | Jan 30, 2024 | Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution ... |
| CVE-2024-21840 | HIGH | 7.1 | 0.1% | Jan 30, 2024 | Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and... |
| CVE-2024-22938 | HIGH | 7.8 | 0.3% | Jan 30, 2024 | Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate pri... |
| CVE-2024-23334 | HIGH | 7.5 | 76.9% | Jan 29, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and c... |
| CVE-2024-24140 | HIGH | 7.2 | 1.2% | Jan 29, 2024 | Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.' |
| CVE-2024-24139 | HIGH | 7.2 | 1.2% | Jan 29, 2024 | Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter. |
| CVE-2024-23940 | HIGH | 7.8 | 0.6% | Jan 29, 2024 | Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and be... |
| CVE-2024-1017 | HIGH | 7.5 | 1.4% | Jan 29, 2024 | A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown ... |
| CVE-2024-1016 | HIGH | 7.5 | 1.4% | Jan 29, 2024 | A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affec... |
| CVE-2024-23828 | HIGH | 8.8 | 1.1% | Jan 29, 2024 | Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execu... |
| CVE-2024-1011 | HIGH | 8.8 | 0.6% | Jan 29, 2024 | A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now