2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1406 | MEDIUM | 4.3 | 0.5% | Feb 10, 2024 | A vulnerability was found in Linksys WRT54GL 4.30.18. It has been declared as problematic. This vulnerability affects un... |
| CVE-2024-0596 | MEDIUM | 5.3 | 0.4% | Feb 10, 2024 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of d... |
| CVE-2024-0595 | MEDIUM | 4.3 | 0.4% | Feb 10, 2024 | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due ... |
| CVE-2024-1405 | MEDIUM | 4.3 | 0.4% | Feb 10, 2024 | A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown par... |
| CVE-2024-25109 | MEDIUM | 5.4 | 0.4% | Feb 9, 2024 | ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface ... |
| CVE-2024-23323 | MEDIUM | 5.3 | 0.5% | Feb 9, 2024 | Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result... |
| CVE-2024-21624 | MEDIUM | 6.5 | 0.5% | Feb 9, 2024 | nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to... |
| CVE-2024-1246 | MEDIUM | 4.8 | 0.5% | Feb 9, 2024 | Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficie... |
| CVE-2024-1245 | MEDIUM | 4.8 | 0.4% | Feb 9, 2024 | Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administra... |
| CVE-2024-1247 | MEDIUM | 4.8 | 1.2% | Feb 9, 2024 | Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient val... |
| CVE-2024-1402 | MEDIUM | 4.3 | 0.5% | Feb 9, 2024 | Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom ... |
| CVE-2024-25454 | MEDIUM | 5.5 | 0.2% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function. |
| CVE-2024-25453 | MEDIUM | 5.5 | 0.3% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function. |
| CVE-2024-25452 | MEDIUM | 5.5 | 0.2% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function. |
| CVE-2024-25451 | MEDIUM | 6.5 | 0.5% | Feb 9, 2024 | Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function. |
| CVE-2024-24776 | MEDIUM | 4.3 | 0.3% | Feb 9, 2024 | Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in chan... |
| CVE-2024-24774 | MEDIUM | 4.1 | 0.5% | Feb 9, 2024 | Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based o... |
| CVE-2024-25679 | MEDIUM | 6.5 | 0.3% | Feb 9, 2024 | In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK... |
| CVE-2024-22119 | MEDIUM | 5.4 | 0.7% | Feb 9, 2024 | The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section. |
| CVE-2024-1122 | MEDIUM | 5.3 | 0.5% | Feb 9, 2024 | The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unaut... |
| CVE-2024-0657 | MEDIUM | 4.8 | 0.3% | Feb 9, 2024 | The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2024-22332 | MEDIUM | 6.5 | 0.6% | Feb 9, 2024 | The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system ... |
| CVE-2024-22318 | MEDIUM | 5.5 | 0.6% | Feb 9, 2024 | IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTL... |
| CVE-2024-24829 | MEDIUM | 5.3 | 0.5% | Feb 9, 2024 | Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for extern... |
| CVE-2024-25107 | MEDIUM | 6.1 | 0.4% | Feb 8, 2024 | WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. On Special:WikiDiscover, ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now