2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25653 | MEDIUM | 4.3 | 0.4% | Mar 14, 2024 | Broken Access Control in the Report functionality of Delinea PAM Secret Server 11.4 allows unprivileged users, when Unli... |
| CVE-2024-25651 | MEDIUM | 5.3 | 0.5% | Mar 14, 2024 | User enumeration can occur in the Authentication REST API in Delinea PAM Secret Server 11.4. This allows a remote attack... |
| CVE-2024-25649 | MEDIUM | 6.7 | 0.1% | Mar 14, 2024 | In Delinea PAM Secret Server 11.4, it is possible for an attacker (with Administrator access to the Secret Server machin... |
| CVE-2024-1223 | MEDIUM | 4.8 | 0.4% | Mar 14, 2024 | This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker... |
| CVE-2024-25650 | MEDIUM | 5.9 | 0.3% | Mar 14, 2024 | Insecure key exchange between Delinea PAM Secret Server 11.4 and the Distributed Engine 8.4.3 allows a PAM administrator... |
| CVE-2024-2242 | MEDIUM | 6.1 | 1.3% | Mar 13, 2024 | The Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘active-tab’ parameter i... |
| CVE-2024-2079 | MEDIUM | 5.4 | 0.3% | Mar 13, 2024 | The WPBakery Page Builder Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-27703 | MEDIUM | 5.4 | 0.5% | Mar 13, 2024 | Cross Site Scripting vulnerability in Leantime 3.0.6 allows a remote attacker to execute arbitrary code via the to-do ti... |
| CVE-2024-28662 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag... |
| CVE-2024-28193 | MEDIUM | 6.5 | 0.6% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 allows users to creat... |
| CVE-2024-28192 | MEDIUM | 5.3 | 0.6% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version <1.8.0 is vulnerable to NoSQ... |
| CVE-2024-28175 | MEDIUM | 5.4 | 0.7% | Mar 13, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of... |
| CVE-2024-27097 | MEDIUM | 5.3 | 0.4% | Mar 13, 2024 | A user endpoint didn't perform filtering on an incoming parameter, which was added directly to the application log. This... |
| CVE-2024-24693 | MEDIUM | 5.5 | 0.2% | Mar 13, 2024 | Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authentica... |
| CVE-2024-24692 | MEDIUM | 4.7 | 0.1% | Mar 13, 2024 | Race condition in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user ... |
| CVE-2024-2431 | MEDIUM | 5.5 | 0.2% | Mar 13, 2024 | An issue in the Palo Alto Networks GlobalProtect app enables a non-privileged user to disable the GlobalProtect app in c... |
| CVE-2024-2403 | MEDIUM | 5.9 | 0.4% | Mar 13, 2024 | Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Wi... |
| CVE-2024-28196 | MEDIUM | 6.1 | 0.4% | Mar 13, 2024 | your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify version < 1.9.0 does not prevent oth... |
| CVE-2024-27953 | MEDIUM | 4.7 | 0.4% | Mar 13, 2024 | Missing Authorization vulnerability in Cool Plugins Cryptocurrency Widgets – Price Ticker & Coins List.This issue affect... |
| CVE-2024-27952 | MEDIUM | 6.1 | 0.4% | Mar 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced... |
| CVE-2024-20322 | MEDIUM | 5.8 | 0.5% | Mar 13, 2024 | A vulnerability in the access control list (ACL) processing on Pseudowire interfaces in the ingress direction of Cisco I... |
| CVE-2024-20319 | MEDIUM | 4.3 | 0.3% | Mar 13, 2024 | A vulnerability in the UDP forwarding code of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to... |
| CVE-2024-20315 | MEDIUM | 5.8 | 0.5% | Mar 13, 2024 | A vulnerability in the access control list (ACL) processing on MPLS interfaces in the ingress direction of Cisco IOS XR ... |
| CVE-2024-20266 | MEDIUM | 5.3 | 0.6% | Mar 13, 2024 | A vulnerability in the DHCP version 4 (DHCPv4) server feature of Cisco IOS XR Software could allow an unauthenticated, r... |
| CVE-2024-20262 | MEDIUM | 6.5 | 0.1% | Mar 13, 2024 | A vulnerability in the Secure Copy Protocol (SCP) and SFTP feature of Cisco IOS XR Software could allow an authenticated... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now