2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1892 | MEDIUM | 6.5 | 0.6% | Feb 28, 2024 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy proj... |
| CVE-2024-26302 | MEDIUM | 4.8 | 0.4% | Feb 27, 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti... |
| CVE-2024-26301 | MEDIUM | 6.5 | 0.5% | Feb 27, 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti... |
| CVE-2024-26300 | MEDIUM | 4.8 | 0.4% | Feb 27, 2024 | A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to condu... |
| CVE-2024-26542 | MEDIUM | 6.1 | 0.5% | Feb 27, 2024 | Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attacke... |
| CVE-2024-26299 | MEDIUM | 4.8 | 0.4% | Feb 27, 2024 | A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at... |
| CVE-2024-25841 | MEDIUM | 5.9 | 0.4% | Feb 27, 2024 | In the module "So Flexibilite" (soflexibilite) from Common-Services for PrestaShop < 4.1.26, a guest (authenticated cust... |
| CVE-2024-21742 | MEDIUM | 5.3 | 1.1% | Feb 27, 2024 | Improper input validation allows for header injection in MIME4J library when using MIME4J DOM for composing message. Thi... |
| CVE-2024-1924 | MEDIUM | 5.3 | 0.5% | Feb 27, 2024 | A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affect... |
| CVE-2024-26144 | MEDIUM | 5.3 | 1.1% | Feb 27, 2024 | Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information lea... |
| CVE-2024-26143 | MEDIUM | 6.1 | 1.0% | Feb 27, 2024 | Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action... |
| CVE-2024-25399 | MEDIUM | 6.1 | 0.3% | Feb 27, 2024 | Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php. |
| CVE-2024-1922 | MEDIUM | 5.4 | 0.5% | Feb 27, 2024 | A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this v... |
| CVE-2024-1919 | MEDIUM | 5.4 | 0.5% | Feb 27, 2024 | A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects ... |
| CVE-2024-1912 | MEDIUM | 4.3 | 0.2% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2024-1910 | MEDIUM | 4.3 | 0.2% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2024-1909 | MEDIUM | 4.3 | 0.2% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2024-1907 | MEDIUM | 4.3 | 0.2% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2024-1906 | MEDIUM | 4.3 | 0.2% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2024-1653 | MEDIUM | 4.3 | 0.3% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-1652 | MEDIUM | 4.3 | 0.3% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-1650 | MEDIUM | 4.3 | 0.3% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-1649 | MEDIUM | 4.3 | 0.3% | Feb 27, 2024 | The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-1106 | MEDIUM | 6.1 | 0.4% | Feb 27, 2024 | The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-0855 | MEDIUM | 5.3 | 0.5% | Feb 27, 2024 | The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now