2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26473 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious J... |
| CVE-2024-26472 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may ... |
| CVE-2024-26471 | MEDIUM | 5.4 | 0.5% | Feb 29, 2024 | A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaS... |
| CVE-2024-26462 | MEDIUM | 5.5 | 0.4% | Feb 29, 2024 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c. |
| CVE-2024-26458 | MEDIUM | 5.3 | 0.8% | Feb 29, 2024 | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. |
| CVE-2024-25831 | MEDIUM | 5.4 | 0.6% | Feb 29, 2024 | F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input ... |
| CVE-2024-25712 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandle... |
| CVE-2024-24708 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a thro... |
| CVE-2024-24155 | MEDIUM | 6.5 | 0.6% | Feb 29, 2024 | Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42a... |
| CVE-2024-24150 | MEDIUM | 6.5 | 0.8% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service vi... |
| CVE-2024-24149 | MEDIUM | 6.5 | 0.8% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service vi... |
| CVE-2024-24147 | MEDIUM | 6.5 | 0.7% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of servic... |
| CVE-2024-24146 | MEDIUM | 6.5 | 0.7% | Feb 29, 2024 | A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service ... |
| CVE-2024-23946 | MEDIUM | 5.3 | 3.1% | Feb 29, 2024 | Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t... |
| CVE-2024-22936 | MEDIUM | 6.1 | 0.6% | Feb 29, 2024 | Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIM... |
| CVE-2024-22251 | MEDIUM | 4.4 | 0.2% | Feb 29, 2024 | VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). ... |
| CVE-2024-21726 | MEDIUM | 6.5 | 48.8% | Feb 29, 2024 | Inadequate content filtering leads to XSS vulnerabilities in various components. |
| CVE-2024-21725 | MEDIUM | 6.1 | 32.2% | Feb 29, 2024 | Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components. |
| CVE-2024-21724 | MEDIUM | 6.1 | 0.5% | Feb 29, 2024 | Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions. |
| CVE-2024-21723 | MEDIUM | 4.3 | 0.5% | Feb 29, 2024 | Inadequate parsing of URLs could result into an open redirect. |
| CVE-2024-21722 | MEDIUM | 6.3 | 0.5% | Feb 29, 2024 | The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modifi... |
| CVE-2024-20344 | MEDIUM | 5.3 | 0.8% | Feb 29, 2024 | A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersi... |
| CVE-2024-20294 | MEDIUM | 6.6 | 0.3% | Feb 29, 2024 | A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software coul... |
| CVE-2024-20291 | MEDIUM | 5.8 | 0.9% | Feb 29, 2024 | A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000... |
| CVE-2024-1970 | MEDIUM | 6.1 | 0.7% | Feb 29, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Online Learning System V2 1.0. Affecte... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now