2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29892 | MEDIUM | 4.9 | 0.8% | Mar 27, 2024 | ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circums... |
| CVE-2024-29888 | MEDIUM | 5.4 | 0.5% | Mar 27, 2024 | Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-coll... |
| CVE-2024-29886 | MEDIUM | 5.3 | 0.3% | Mar 27, 2024 | Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old passw... |
| CVE-2024-28860 | MEDIUM | 6.8 | 0.2% | Mar 27, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent en... |
| CVE-2024-28247 | MEDIUM | 6.5 | 1.4% | Mar 27, 2024 | The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side softwa... |
| CVE-2024-28233 | MEDIUM | 6.1 | 0.3% | Mar 27, 2024 | JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdo... |
| CVE-2024-23451 | MEDIUM | 6.5 | 0.4% | Mar 27, 2024 | Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently... |
| CVE-2024-20333 | MEDIUM | 4.3 | 0.4% | Mar 27, 2024 | A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow a... |
| CVE-2024-20324 | MEDIUM | 5.5 | 0.1% | Mar 27, 2024 | A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to acce... |
| CVE-2024-20316 | MEDIUM | 5.3 | 0.5% | Mar 27, 2024 | A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remo... |
| CVE-2024-20309 | MEDIUM | 5.5 | 0.1% | Mar 27, 2024 | A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, lo... |
| CVE-2024-20306 | MEDIUM | 6.7 | 0.2% | Mar 27, 2024 | A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authentica... |
| CVE-2024-20278 | MEDIUM | 6.5 | 0.5% | Mar 27, 2024 | A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate... |
| CVE-2024-20265 | MEDIUM | 5.9 | 0.2% | Mar 27, 2024 | A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacke... |
| CVE-2024-29765 | MEDIUM | 6.5 | 0.3% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alireza Sedghi Apa... |
| CVE-2024-29764 | MEDIUM | 6.5 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Molongui allows St... |
| CVE-2024-29763 | MEDIUM | 6.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WordPre... |
| CVE-2024-29762 | MEDIUM | 6.5 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jory Hogeveen Off-... |
| CVE-2024-29761 | MEDIUM | 6.5 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Krunal Prajapati W... |
| CVE-2024-29760 | MEDIUM | 6.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl LLC Boost... |
| CVE-2024-29759 | MEDIUM | 6.1 | 0.4% | Mar 27, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodePeople Calcula... |
| CVE-2024-28853 | MEDIUM | 5.9 | 0.6% | Mar 27, 2024 | Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerabili... |
| CVE-2024-28852 | MEDIUM | 6.1 | 0.5% | Mar 27, 2024 | Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabi... |
| CVE-2024-26652 | MEDIUM | 4.1 | 0.3% | Mar 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: pds_core: Fix possible double free in error ha... |
| CVE-2024-26651 | MEDIUM | 5.5 | 0.3% | Mar 27, 2024 | In the Linux kernel, the following vulnerability has been resolved: sr9800: Add check for usbnet_get_endpoints Add che... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now