2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20736 | MEDIUM | 5.5 | 3.2% | Feb 15, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that ... |
| CVE-2024-20735 | MEDIUM | 5.5 | 2.3% | Feb 15, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds read vulnerability that ... |
| CVE-2024-20734 | MEDIUM | 5.5 | 3.3% | Feb 15, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2024-20733 | MEDIUM | 5.5 | 3.4% | Feb 15, 2024 | Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an Improper Input Validation vulnerabilit... |
| CVE-2024-20725 | MEDIUM | 5.5 | 0.2% | Feb 15, 2024 | Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2024-20724 | MEDIUM | 5.5 | 0.2% | Feb 15, 2024 | Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2024-20722 | MEDIUM | 5.5 | 0.2% | Feb 15, 2024 | Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to ... |
| CVE-2024-24256 | MEDIUM | 5.9 | 0.4% | Feb 15, 2024 | SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an ... |
| CVE-2024-21727 | MEDIUM | 6.1 | 0.3% | Feb 15, 2024 | XSS vulnerability in DP Calendar component for Joomla. |
| CVE-2024-0708 | MEDIUM | 5.3 | 0.5% | Feb 15, 2024 | The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitiv... |
| CVE-2024-25940 | MEDIUM | 6.3 | 0.5% | Feb 15, 2024 | `bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected v... |
| CVE-2024-25559 | MEDIUM | 4.7 | 0.4% | Feb 15, 2024 | URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request... |
| CVE-2024-25620 | MEDIUM | 6.4 | 0.6% | Feb 15, 2024 | Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm cli... |
| CVE-2024-1471 | MEDIUM | 4.8 | 0.4% | Feb 14, 2024 | An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Sec... |
| CVE-2024-25619 | MEDIUM | 4.3 | 0.4% | Feb 14, 2024 | Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the ... |
| CVE-2024-1482 | MEDIUM | 6.5 | 0.4% | Feb 14, 2024 | An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create n... |
| CVE-2024-25300 | MEDIUM | 4.8 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML v... |
| CVE-2024-0011 | MEDIUM | 6.1 | 0.4% | Feb 14, 2024 | A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software... |
| CVE-2024-0010 | MEDIUM | 6.1 | 0.5% | Feb 14, 2024 | A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS so... |
| CVE-2024-0009 | MEDIUM | 6.3 | 0.2% | Feb 14, 2024 | An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enable... |
| CVE-2024-0007 | MEDIUM | 4.8 | 0.4% | Feb 14, 2024 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-... |
| CVE-2024-24966 | MEDIUM | 5.5 | 0.2% | Feb 14, 2024 | When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly autho... |
| CVE-2024-23976 | MEDIUM | 6 | 0.2% | Feb 14, 2024 | When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Applianc... |
| CVE-2024-23607 | MEDIUM | 5.5 | 0.5% | Feb 14, 2024 | A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read fil... |
| CVE-2024-21782 | MEDIUM | 6.7 | 0.2% | Feb 14, 2024 | BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but d... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now