2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27906 | MEDIUM | 5.9 | 0.3% | Feb 29, 2024 | Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import e... |
| CVE-2024-1953 | MEDIUM | 4.3 | 0.5% | Feb 29, 2024 | Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of ro... |
| CVE-2024-1952 | MEDIUM | 4.3 | 0.4% | Feb 29, 2024 | Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemer... |
| CVE-2024-1942 | MEDIUM | 4.3 | 0.4% | Feb 29, 2024 | Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing ... |
| CVE-2024-1888 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member... |
| CVE-2024-24988 | MEDIUM | 6.5 | 0.7% | Feb 29, 2024 | Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to s... |
| CVE-2024-23493 | MEDIUM | 6.5 | 0.4% | Feb 29, 2024 | Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch de... |
| CVE-2024-23488 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members... |
| CVE-2024-1887 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is... |
| CVE-2024-25594 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress De... |
| CVE-2024-1978 | MEDIUM | 5.5 | 0.5% | Feb 29, 2024 | The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.... |
| CVE-2024-25098 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB ... |
| CVE-2024-25094 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicola... |
| CVE-2024-25093 | MEDIUM | 6.1 | 0.4% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD ... |
| CVE-2024-23501 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Eboo... |
| CVE-2024-21752 | MEDIUM | 6.1 | 0.2% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affe... |
| CVE-2024-1977 | MEDIUM | 4.8 | 0.4% | Feb 29, 2024 | The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist... |
| CVE-2024-1976 | MEDIUM | 4.3 | 0.2% | Feb 29, 2024 | The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2024-1437 | MEDIUM | 6.1 | 0.4% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Ads... |
| CVE-2024-1434 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Media A... |
| CVE-2024-1341 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe s... |
| CVE-2024-0689 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versio... |
| CVE-2024-27517 | MEDIUM | 5.4 | 0.4% | Feb 29, 2024 | Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code afte... |
| CVE-2024-27092 | MEDIUM | 5.4 | 0.6% | Feb 29, 2024 | Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad... |
| CVE-2024-27083 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerabil... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now