2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20685 | MEDIUM | 5.9 | 5.5% | Apr 9, 2024 | Azure Private 5G Core Denial of Service Vulnerability |
| CVE-2024-20669 | MEDIUM | 6.7 | 0.6% | Apr 9, 2024 | Secure Boot Security Feature Bypass Vulnerability |
| CVE-2024-20665 | MEDIUM | 6.7 | 0.7% | Apr 9, 2024 | BitLocker Security Feature Bypass Vulnerability |
| CVE-2024-31868 | MEDIUM | 6.1 | 1.3% | Apr 9, 2024 | Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can modify helium.json and expo... |
| CVE-2024-31865 | MEDIUM | 6.5 | 1.7% | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. The attackers can call updating cron API with invalid or im... |
| CVE-2024-28235 | MEDIUM | 6.5 | 0.7% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.9.0 and prior to versions 4.13.40 and 5.3.4, w... |
| CVE-2024-31487 | MEDIUM | 6.5 | 0.9% | Apr 9, 2024 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2024-28234 | MEDIUM | 4.7 | 0.6% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 2.0.0 and prior to versions 4.13.40 and 5.3.4, i... |
| CVE-2024-28191 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, it... |
| CVE-2024-28190 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | Contao is an open source content management system. Starting in version 4.0.0 and prior to version 4.13.40 and 5.3.4, us... |
| CVE-2024-31544 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to exec... |
| CVE-2024-31863 | MEDIUM | 5.3 | 1.0% | Apr 9, 2024 | Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin.This issue affects Apa... |
| CVE-2024-31862 | MEDIUM | 5.3 | 1.4% | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affect... |
| CVE-2024-31860 | MEDIUM | 6.5 | 1.4% | Apr 9, 2024 | Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can s... |
| CVE-2024-31369 | MEDIUM | 5.4 | 0.2% | Apr 9, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.... |
| CVE-2024-31368 | MEDIUM | 6.5 | 0.4% | Apr 9, 2024 | Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2. |
| CVE-2024-30190 | MEDIUM | 6.1 | 0.2% | Apr 9, 2024 | A vulnerability has been identified in SCALANCE W1748-1 M12 (6GK5748-1GY01-0AA0), SCALANCE W1748-1 M12 (6GK5748-1GY01-0T... |
| CVE-2024-30189 | MEDIUM | 6.1 | 0.2% | Apr 9, 2024 | A vulnerability has been identified in SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0) (All versions), SCALANCE W721-1 RJ45 (6... |
| CVE-2024-26277 | MEDIUM | 4.8 | 0.2% | Apr 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa... |
| CVE-2024-26276 | MEDIUM | 5.5 | 0.2% | Apr 9, 2024 | A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Pa... |
| CVE-2024-1664 | MEDIUM | 6.1 | 0.5% | Apr 9, 2024 | The Responsive Gallery Grid WordPress plugin before 2.3.11 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-30218 | MEDIUM | 6.5 | 0.5% | Apr 9, 2024 | The ABAP Application Server of SAP NetWeaver as well as ABAP Platform allows an attacker to prevent legitimate users fro... |
| CVE-2024-30217 | MEDIUM | 4.3 | 0.3% | Apr 9, 2024 | Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ... |
| CVE-2024-30216 | MEDIUM | 4.3 | 0.3% | Apr 9, 2024 | Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in ... |
| CVE-2024-30215 | MEDIUM | 4.8 | 0.3% | Apr 9, 2024 | The Resource Settings page allows a high privilege attacker to load exploitable payload to be stored and reflected whene... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now