2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28156 | MEDIUM | 5.4 | 80.2% | Mar 6, 2024 | Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resultin... |
| CVE-2024-28155 | MEDIUM | 4.3 | 0.4% | Mar 6, 2024 | Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attac... |
| CVE-2024-28154 | MEDIUM | 6.5 | 0.7% | Mar 6, 2024 | Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in... |
| CVE-2024-28153 | MEDIUM | 5.4 | 0.7% | Mar 6, 2024 | Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check rep... |
| CVE-2024-28152 | MEDIUM | 6.3 | 0.6% | Mar 6, 2024 | In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discove... |
| CVE-2024-28151 | MEDIUM | 4.3 | 0.9% | Mar 6, 2024 | Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recre... |
| CVE-2024-28150 | MEDIUM | 4.7 | 0.7% | Mar 6, 2024 | Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as p... |
| CVE-2024-28149 | MEDIUM | 6.5 | 0.7% | Mar 6, 2024 | Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers wi... |
| CVE-2024-20346 | MEDIUM | 5.4 | 0.4% | Mar 6, 2024 | A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remo... |
| CVE-2024-20345 | MEDIUM | 6.5 | 2.2% | Mar 6, 2024 | A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote at... |
| CVE-2024-20336 | MEDIUM | 6.5 | 0.8% | Mar 6, 2024 | A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allo... |
| CVE-2024-20335 | MEDIUM | 6.5 | 1.0% | Mar 6, 2024 | A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs coul... |
| CVE-2024-20301 | MEDIUM | 6.2 | 0.3% | Mar 6, 2024 | A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to... |
| CVE-2024-20292 | MEDIUM | 5.5 | 0.1% | Mar 6, 2024 | A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authentica... |
| CVE-2024-25103 | MEDIUM | 6.3 | 0.2% | Mar 6, 2024 | This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with... |
| CVE-2024-2211 | MEDIUM | 6.1 | 0.3% | Mar 6, 2024 | Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacke... |
| CVE-2024-26627 | MEDIUM | 5.5 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock ... |
| CVE-2024-26626 | MEDIUM | 5.5 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packet... |
| CVE-2024-26623 | MEDIUM | 4.7 | 0.2% | Mar 6, 2024 | In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq ... |
| CVE-2024-1989 | MEDIUM | 5.4 | 0.5% | Mar 6, 2024 | The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-1771 | MEDIUM | 4.3 | 0.4% | Mar 6, 2024 | The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on th... |
| CVE-2024-1760 | MEDIUM | 4.7 | 0.3% | Mar 6, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cro... |
| CVE-2024-27278 | MEDIUM | 5.4 | 0.3% | Mar 6, 2024 | OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which us... |
| CVE-2024-24785 | MEDIUM | 5.4 | 0.8% | Mar 5, 2024 | If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-... |
| CVE-2024-24783 | MEDIUM | 5.9 | 0.7% | Mar 5, 2024 | Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.V... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now