2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25980 | MEDIUM | 5.3 | 0.5% | Feb 19, 2024 | Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other grou... |
| CVE-2024-25979 | MEDIUM | 5.3 | 0.6% | Feb 19, 2024 | The URL parameters accepted by forum search were not limited to the allowed parameters. |
| CVE-2024-1346 | MEDIUM | 5.5 | 0.4% | Feb 19, 2024 | Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to cal... |
| CVE-2024-1345 | MEDIUM | 5.5 | 0.2% | Feb 19, 2024 | Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to per... |
| CVE-2024-1343 | MEDIUM | 5.5 | 0.1% | Feb 19, 2024 | A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allow... |
| CVE-2024-26308 | MEDIUM | 5.5 | 0.9% | Feb 19, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache ... |
| CVE-2024-25710 | MEDIUM | 5.5 | 0.4% | Feb 19, 2024 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apach... |
| CVE-2024-26328 | MEDIUM | 6 | 0.3% | Feb 19, 2024 | An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIO... |
| CVE-2024-26327 | MEDIUM | 5.3 | 0.5% | Feb 19, 2024 | An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where ... |
| CVE-2024-26318 | MEDIUM | 6.1 | 0.4% | Feb 19, 2024 | Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / ... |
| CVE-2024-22337 | MEDIUM | 5.5 | 0.2% | Feb 17, 2024 | IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall... |
| CVE-2024-22336 | MEDIUM | 5.5 | 0.2% | Feb 17, 2024 | IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall... |
| CVE-2024-22335 | MEDIUM | 5.5 | 0.2% | Feb 17, 2024 | IBM QRadar Suite 1.10.12.0 through 1.10.17.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores potentiall... |
| CVE-2024-25297 | MEDIUM | 4.8 | 0.6% | Feb 17, 2024 | Cross Site Scripting (XSS) vulnerability in Bludit CMS version 3.15, allows remote attackers to execute arbitrary code a... |
| CVE-2024-21500 | MEDIUM | 6.5 | 0.5% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authe... |
| CVE-2024-21499 | MEDIUM | 4.3 | 0.5% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forward... |
| CVE-2024-21498 | MEDIUM | 5.3 | 0.6% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via ... |
| CVE-2024-21497 | MEDIUM | 6.1 | 0.5% | Feb 17, 2024 | Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url paramet... |
| CVE-2024-21496 | MEDIUM | 6.1 | 0.6% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Cross-site Scripting (XSS) via the Refe... |
| CVE-2024-21494 | MEDIUM | 5.4 | 0.5% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via t... |
| CVE-2024-21493 | MEDIUM | 5.3 | 0.7% | Feb 17, 2024 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when... |
| CVE-2024-20986 | MEDIUM | 6.1 | 0.2% | Feb 17, 2024 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t... |
| CVE-2024-20984 | MEDIUM | 4.4 | 1.0% | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server : Security : Firewall). Supported versions... |
| CVE-2024-20982 | MEDIUM | 4.9 | 1.1% | Feb 17, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2024-20980 | MEDIUM | 5.4 | 0.3% | Feb 17, 2024 | Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server). Supported versions that a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now