2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26590 | MEDIUM | 5.5 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: erofs: fix inconsistent per-file compression format... |
| CVE-2024-26587 | MEDIUM | 5.5 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PH... |
| CVE-2024-26586 | MEDIUM | 6.7 | 0.2% | Feb 22, 2024 | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption Whe... |
| CVE-2024-25828 | MEDIUM | 4.9 | 0.6% | Feb 22, 2024 | cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php. |
| CVE-2024-26284 | MEDIUM | 6.1 | 0.3% | Feb 22, 2024 | Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, ... |
| CVE-2024-26281 | MEDIUM | 4.7 | 0.3% | Feb 22, 2024 | Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the cur... |
| CVE-2024-26445 | MEDIUM | 6.1 | 0.2% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_pla... |
| CVE-2024-26351 | MEDIUM | 6.1 | 0.2% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_pla... |
| CVE-2024-26349 | MEDIUM | 4.3 | 0.3% | Feb 22, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_tra... |
| CVE-2024-25876 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr... |
| CVE-2024-25875 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitr... |
| CVE-2024-25874 | MEDIUM | 5.4 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to exec... |
| CVE-2024-25873 | MEDIUM | 5.4 | 0.5% | Feb 22, 2024 | Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote m... |
| CVE-2024-26578 | MEDIUM | 5.9 | 0.9% | Feb 22, 2024 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answ... |
| CVE-2024-23349 | MEDIUM | 5.4 | 1.1% | Feb 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This... |
| CVE-2024-26491 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CM... |
| CVE-2024-26490 | MEDIUM | 5.4 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execut... |
| CVE-2024-26489 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allo... |
| CVE-2024-1053 | MEDIUM | 4.3 | 0.4% | Feb 22, 2024 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2024-0903 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera... |
| CVE-2024-26484 | MEDIUM | 6.1 | 0.4% | Feb 22, 2024 | A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers... |
| CVE-2024-26481 | MEDIUM | 4.7 | 0.4% | Feb 22, 2024 | Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter. |
| CVE-2024-25801 | MEDIUM | 6.1 | 0.3% | Feb 22, 2024 | SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload i... |
| CVE-2024-1525 | MEDIUM | 5.3 | 0.5% | Feb 22, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions start... |
| CVE-2024-0861 | MEDIUM | 4.3 | 0.4% | Feb 22, 2024 | An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now