2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25151 | MEDIUM | 5.4 | 0.5% | Feb 21, 2024 | The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before se... |
| CVE-2024-1676 | MEDIUM | 5.4 | 18.6% | Feb 21, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof se... |
| CVE-2024-1672 | MEDIUM | 5.4 | 0.9% | Feb 21, 2024 | Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacke... |
| CVE-2024-1671 | MEDIUM | 6.5 | 0.7% | Feb 21, 2024 | Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypa... |
| CVE-2024-1562 | MEDIUM | 5.3 | 0.4% | Feb 21, 2024 | The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-1501 | MEDIUM | 4.7 | 0.3% | Feb 21, 2024 | The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2024-26269 | MEDIUM | 6.1 | 0.6% | Feb 21, 2024 | Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37... |
| CVE-2024-26266 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupport... |
| CVE-2024-25603 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 thr... |
| CVE-2024-25602 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7... |
| CVE-2024-25601 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 th... |
| CVE-2024-25152 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older... |
| CVE-2024-25147 | MEDIUM | 6.1 | 0.6% | Feb 21, 2024 | Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsup... |
| CVE-2024-0407 | MEDIUM | 6.5 | 0.3% | Feb 21, 2024 | Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, w... |
| CVE-2024-26140 | MEDIUM | 6.1 | 0.4% | Feb 20, 2024 | com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5... |
| CVE-2024-25428 | MEDIUM | 6.5 | 0.4% | Feb 20, 2024 | SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter. |
| CVE-2024-25631 | MEDIUM | 5.3 | 0.2% | Feb 20, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have ena... |
| CVE-2024-25630 | MEDIUM | 5.3 | 0.2% | Feb 20, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are usin... |
| CVE-2024-25260 | MEDIUM | 4 | 0.3% | Feb 20, 2024 | elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. |
| CVE-2024-24763 | MEDIUM | 6.1 | 1.1% | Feb 20, 2024 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.... |
| CVE-2024-25366 | MEDIUM | 6.2 | 0.9% | Feb 20, 2024 | Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of serv... |
| CVE-2024-26270 | MEDIUM | 5.3 | 0.4% | Feb 20, 2024 | The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 u... |
| CVE-2024-26268 | MEDIUM | 5.3 | 0.5% | Feb 20, 2024 | User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP... |
| CVE-2024-25197 | MEDIUM | 6.5 | 0.7% | Feb 20, 2024 | Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dere... |
| CVE-2024-1556 | MEDIUM | 6.5 | 0.5% | Feb 20, 2024 | The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and und... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now