2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28949 | MEDIUM | 6.5 | 0.6% | Apr 5, 2024 | Mattermost Server versions 9.5.x before 9.5.2, 9.4.x before 9.4.4, 9.3.x before 9.3.3, 8.1.x before 8.1.11 don't limit t... |
| CVE-2024-27437 | MEDIUM | 5.5 | 0.2% | Apr 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Disable auto-enable of exclusive INTx IRQ... |
| CVE-2024-26814 | MEDIUM | 5.5 | 0.2% | Apr 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: vfio/fsl-mc: Block calling interrupt handler withou... |
| CVE-2024-26813 | MEDIUM | 5.5 | 0.2% | Apr 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: vfio/platform: Create persistent IRQ handlers The ... |
| CVE-2024-26812 | MEDIUM | 5.5 | 0.2% | Apr 5, 2024 | In the Linux kernel, the following vulnerability has been resolved: vfio/pci: Create persistent INTx handler A vulnera... |
| CVE-2024-26329 | MEDIUM | 6.2 | 0.3% | Apr 5, 2024 | Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBy... |
| CVE-2024-2509 | MEDIUM | 6.5 | 0.4% | Apr 5, 2024 | The Gutenberg Blocks by Kadence Blocks WordPress plugin before 3.2.26 does not validate and escape some of its block opt... |
| CVE-2024-3321 | MEDIUM | 4.8 | 0.5% | Apr 5, 2024 | A vulnerability classified as problematic has been found in SourceCodester eLearning System 1.0. This affects an unknown... |
| CVE-2024-3320 | MEDIUM | 6.1 | 0.6% | Apr 5, 2024 | A vulnerability was found in SourceCodester eLearning System 1.0. It has been rated as problematic. Affected by this iss... |
| CVE-2024-29981 | MEDIUM | 4.3 | 0.7% | Apr 4, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-29049 | MEDIUM | 4.7 | 0.7% | Apr 4, 2024 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability |
| CVE-2024-31204 | MEDIUM | 6.1 | 8.2% | Apr 4, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie... |
| CVE-2024-30270 | MEDIUM | 6.2 | 27.3% | Apr 4, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie... |
| CVE-2024-29386 | MEDIUM | 5.4 | 0.4% | Apr 4, 2024 | projeqtor up to 11.2.0 was discovered to contain a SQL injection vulnerability via the component /view/criticalResourceE... |
| CVE-2024-24795 | MEDIUM | 6.3 | 2.9% | Apr 4, 2024 | HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response ... |
| CVE-2024-22023 | MEDIUM | 5.3 | 3.0% | Apr 4, 2024 | An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Se... |
| CVE-2024-30254 | MEDIUM | 5.8 | 0.2% | Apr 4, 2024 | MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1... |
| CVE-2024-29193 | MEDIUM | 6.1 | 0.5% | Apr 4, 2024 | gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to DOM-based cross-site scripting. Th... |
| CVE-2024-2660 | MEDIUM | 6.8 | 0.3% | Apr 4, 2024 | Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP ... |
| CVE-2024-25709 | MEDIUM | 6.1 | 0.5% | Apr 4, 2024 | There is a stored Cross‑Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS versions 11.2 and below that may al... |
| CVE-2024-25708 | MEDIUM | 4.8 | 0.4% | Apr 4, 2024 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 10.9.... |
| CVE-2024-25706 | MEDIUM | 6.1 | 0.4% | Apr 4, 2024 | There is an HTML injection vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticat... |
| CVE-2024-25705 | MEDIUM | 5.4 | 0.5% | Apr 4, 2024 | There is a cross‑site scripting (XSS) vulnerability in Esri Portal for ArcGIS Experience Builder versions 11.1 and below... |
| CVE-2024-25700 | MEDIUM | 4.8 | 0.4% | Apr 4, 2024 | There is a stored Cross-site Scripting vulnerability in Esri Portal for ArcGIS Enterprise Web App Builder versions 11.1 ... |
| CVE-2024-25698 | MEDIUM | 6.1 | 0.4% | Apr 4, 2024 | There is a reflected cross site scripting vulnerability in the home application in Esri Portal for ArcGIS 11.1 and below... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now