2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27968 | MEDIUM | 6.1 | 0.2% | Mar 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue... |
| CVE-2024-27965 | MEDIUM | 4.8 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnel... |
| CVE-2024-27963 | MEDIUM | 5.4 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Store... |
| CVE-2024-27962 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan... |
| CVE-2024-27277 | MEDIUM | 5.5 | 0.1% | Mar 21, 2024 | The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining... |
| CVE-2024-2464 | MEDIUM | 6.3 | 0.5% | Mar 21, 2024 | This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the u... |
| CVE-2024-29244 | MEDIUM | 5.3 | 0.5% | Mar 21, 2024 | Shenzhen Libituo Technology Co., Ltd LBT-T300-mini v1.2.9 was discovered to contain a buffer overflow via the pin_code_3... |
| CVE-2024-27995 | MEDIUM | 5.4 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Repute Infosystems... |
| CVE-2024-2494 | MEDIUM | 6.2 | 0.4% | Mar 21, 2024 | A flaw was found in the RPC library APIs of libvirt. The RPC server deserialization code allocates memory for arrays bef... |
| CVE-2024-29879 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/... |
| CVE-2024-29878 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/sitepreference/add, 'descrip... |
| CVE-2024-29877 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/e... |
| CVE-2024-28834 | MEDIUM | 5.3 | 0.7% | Mar 21, 2024 | A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in ... |
| CVE-2024-26643 | MEDIUM | 5.5 | 0.2% | Mar 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: mark set as dead when unbindi... |
| CVE-2024-26642 | MEDIUM | 5.5 | 0.3% | Mar 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: disallow anonymous set with t... |
| CVE-2024-26307 | MEDIUM | 5.3 | 0.2% | Mar 21, 2024 | Possible race condition vulnerability in Apache Doris. Some of code using `chmod()` method. This method run the risk of ... |
| CVE-2024-29133 | MEDIUM | 5.4 | 1.7% | Mar 21, 2024 | Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from ... |
| CVE-2024-28835 | MEDIUM | 5 | 0.4% | Mar 21, 2024 | A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially cra... |
| CVE-2024-28635 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | Cross Site Scripting (XSS) vulnerability in SurveyJS Survey Creator v.1.9.132 and before, allows attackers to execute ar... |
| CVE-2024-22724 | MEDIUM | 6.6 | 0.3% | Mar 21, 2024 | An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrar... |
| CVE-2024-2713 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | A vulnerability, which was classified as critical, was found in Campcodes Complete Online DJ Booking System 1.0. Affecte... |
| CVE-2024-2712 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | A vulnerability, which was classified as critical, has been found in Campcodes Complete Online DJ Booking System 1.0. Th... |
| CVE-2024-28102 | MEDIUM | 6.8 | 1.0% | Mar 21, 2024 | JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to version 1.5.6, an attacker can ... |
| CVE-2024-27936 | MEDIUM | 6.5 | 0.9% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to ... |
| CVE-2024-27932 | MEDIUM | 4.6 | 0.6% | Mar 21, 2024 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.8.0 and prior to version 1.40.4, Deno i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now