2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21429 | MEDIUM | 6.8 | 0.9% | Mar 12, 2024 | Windows USB Hub Driver Remote Code Execution Vulnerability |
| CVE-2024-21419 | MEDIUM | 5.4 | 1.1% | Mar 12, 2024 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability |
| CVE-2024-21408 | MEDIUM | 5.5 | 4.5% | Mar 12, 2024 | Windows Hyper-V Denial of Service Vulnerability |
| CVE-2024-20671 | MEDIUM | 5.5 | 0.9% | Mar 12, 2024 | Microsoft Defender Security Feature Bypass Vulnerability |
| CVE-2024-1529 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | Vulnerability in CMS Made Simple 2.2.14, which does not sufficiently encode user-controlled input, resulting in a Cross-... |
| CVE-2024-1528 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | CMS Made Simple version 2.2.14, does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting ... |
| CVE-2024-1304 | MEDIUM | 6.1 | 0.7% | Mar 12, 2024 | Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerab... |
| CVE-2024-1303 | MEDIUM | 6.5 | 1.0% | Mar 12, 2024 | Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up ... |
| CVE-2024-1302 | MEDIUM | 5.5 | 0.5% | Mar 12, 2024 | Information exposure vulnerability in Badger Meter Monitool affecting versions up to 4.6.3 and earlier. A local attacker... |
| CVE-2024-23112 | MEDIUM | 4.3 | 0.7% | Mar 12, 2024 | An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7.4.0 through 7.4.1, 7.2.... |
| CVE-2024-21761 | MEDIUM | 4.3 | 0.4% | Mar 12, 2024 | An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may... |
| CVE-2024-1227 | MEDIUM | 6.5 | 0.5% | Mar 12, 2024 | An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a ... |
| CVE-2024-2049 | MEDIUM | 5.3 | 0.4% | Mar 12, 2024 | Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 al... |
| CVE-2024-2391 | MEDIUM | 6.1 | 0.5% | Mar 12, 2024 | A vulnerability was found in EVE-NG 5.0.1-13 and classified as problematic. Affected by this issue is some unknown funct... |
| CVE-2024-22045 | MEDIUM | 6.5 | 0.4% | Mar 12, 2024 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensit... |
| CVE-2024-21483 | MEDIUM | 5.1 | 0.2% | Mar 12, 2024 | A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 o... |
| CVE-2024-2371 | MEDIUM | 6.2 | 0.2% | Mar 12, 2024 | Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol ... |
| CVE-2024-27279 | MEDIUM | 6.5 | 0.8% | Mar 12, 2024 | Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.... |
| CVE-2024-26005 | MEDIUM | 4.8 | 0.6% | Mar 12, 2024 | An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restar... |
| CVE-2024-25997 | MEDIUM | 5.3 | 0.7% | Mar 12, 2024 | An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file... |
| CVE-2024-25994 | MEDIUM | 5.3 | 0.7% | Mar 12, 2024 | An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload desti... |
| CVE-2024-1328 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all ver... |
| CVE-2024-0906 | MEDIUM | 5.3 | 0.5% | Mar 12, 2024 | The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in... |
| CVE-2024-24964 | MEDIUM | 6.3 | 0.4% | Mar 12, 2024 | Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prio... |
| CVE-2024-21584 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now