2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2204 | MEDIUM | 5.5 | 0.2% | Mar 15, 2024 | Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 an... |
| CVE-2024-2180 | MEDIUM | 5.5 | 0.3% | Mar 15, 2024 | Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IO... |
| CVE-2024-26454 | MEDIUM | 5.4 | 0.4% | Mar 15, 2024 | A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1... |
| CVE-2024-26163 | MEDIUM | 4.7 | 2.1% | Mar 14, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2024-1853 | MEDIUM | 5.5 | 0.2% | Mar 14, 2024 | Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x8000... |
| CVE-2024-2249 | MEDIUM | 5.4 | 0.3% | Mar 14, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWr... |
| CVE-2024-26475 | MEDIUM | 5.5 | 0.3% | Mar 14, 2024 | An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of ... |
| CVE-2024-2256 | MEDIUM | 5.4 | 0.4% | Mar 14, 2024 | The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact... |
| CVE-2024-27265 | MEDIUM | 6.5 | 0.2% | Mar 14, 2024 | IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an atta... |
| CVE-2024-24770 | MEDIUM | 5.3 | 0.4% | Mar 14, 2024 | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le... |
| CVE-2024-24562 | MEDIUM | 5.3 | 0.3% | Mar 14, 2024 | vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers ar... |
| CVE-2024-23823 | MEDIUM | 6.5 | 0.3% | Mar 14, 2024 | vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le... |
| CVE-2024-28849 | MEDIUM | 6.5 | 1.0% | Mar 14, 2024 | follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows... |
| CVE-2024-28323 | MEDIUM | 6.5 | 0.4% | Mar 14, 2024 | The bwdates-report-result.php file in Phpgurukul User Registration & Login and User Management System 3.1 contains a pot... |
| CVE-2024-25156 | MEDIUM | 6.5 | 0.4% | Mar 14, 2024 | A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-sp... |
| CVE-2024-28418 | MEDIUM | 6.5 | 0.4% | Mar 14, 2024 | Webedition CMS 9.2.2.0 has a File upload vulnerability via /webEdition/we_cmd.php |
| CVE-2024-28417 | MEDIUM | 6.3 | 0.3% | Mar 14, 2024 | Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php. |
| CVE-2024-27986 | MEDIUM | 5.4 | 0.3% | Mar 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Livemesh Elementor... |
| CVE-2024-0313 | MEDIUM | 5.5 | 0.2% | Mar 14, 2024 | A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organiza... |
| CVE-2024-0312 | MEDIUM | 5.5 | 0.2% | Mar 14, 2024 | A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password. |
| CVE-2024-0311 | MEDIUM | 5.5 | 0.4% | Mar 14, 2024 | A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code. |
| CVE-2024-22398 | MEDIUM | 4.9 | 0.9% | Mar 14, 2024 | An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Securit... |
| CVE-2024-22396 | MEDIUM | 5.3 | 1.1% | Mar 14, 2024 | An Integer-based buffer overflow vulnerability in the SonicOS via IPSec allows a remote attacker in specific conditions ... |
| CVE-2024-1884 | MEDIUM | 6.5 | 37.9% | Mar 14, 2024 | This is a Server-Side Request Forgery (SSRF) vulnerability in the PaperCut NG/MF server-side module that allows an atta... |
| CVE-2024-1883 | MEDIUM | 6.1 | 61.5% | Mar 14, 2024 | This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now