2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22021 | MEDIUM | 4.3 | 0.4% | Feb 7, 2024 | Vulnerability CVE-2024-22021 allows a Veeam Recovery Orchestrator user with a low privileged role (Plan Author) to retri... |
| CVE-2024-1267 | MEDIUM | 6.1 | 0.4% | Feb 7, 2024 | A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by... |
| CVE-2024-1266 | MEDIUM | 6.1 | 0.5% | Feb 7, 2024 | A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vuln... |
| CVE-2024-1265 | MEDIUM | 4.8 | 0.5% | Feb 7, 2024 | A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an u... |
| CVE-2024-0971 | MEDIUM | 6.5 | 0.8% | Feb 7, 2024 | A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter sca... |
| CVE-2024-0955 | MEDIUM | 4.8 | 0.6% | Feb 7, 2024 | A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus a... |
| CVE-2024-24255 | MEDIUM | 4.2 | 0.3% | Feb 6, 2024 | A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows... |
| CVE-2024-24254 | MEDIUM | 4.2 | 0.4% | Feb 6, 2024 | PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condi... |
| CVE-2024-1258 | MEDIUM | 5.9 | 0.6% | Feb 6, 2024 | A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerab... |
| CVE-2024-22241 | MEDIUM | 4.8 | 37.8% | Feb 6, 2024 | Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can ... |
| CVE-2024-22240 | MEDIUM | 4.9 | 0.6% | Feb 6, 2024 | Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may explo... |
| CVE-2024-22238 | MEDIUM | 4.8 | 0.5% | Feb 6, 2024 | Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may ... |
| CVE-2024-1257 | MEDIUM | 6.1 | 0.5% | Feb 6, 2024 | A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of t... |
| CVE-2024-1256 | MEDIUM | 4.3 | 0.6% | Feb 6, 2024 | A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of... |
| CVE-2024-22331 | MEDIUM | 5.5 | 0.2% | Feb 6, 2024 | IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM... |
| CVE-2024-24291 | MEDIUM | 6.1 | 0.4% | Feb 6, 2024 | An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a c... |
| CVE-2024-23344 | MEDIUM | 6.5 | 0.5% | Feb 6, 2024 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get ac... |
| CVE-2024-24594 | MEDIUM | 5.4 | 0.6% | Feb 6, 2024 | A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform ... |
| CVE-2024-0911 | MEDIUM | 5.5 | 0.3% | Feb 6, 2024 | A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into proce... |
| CVE-2024-0690 | MEDIUM | 5.5 | 0.3% | Feb 6, 2024 | An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in... |
| CVE-2024-24943 | MEDIUM | 5.5 | 0.4% | Feb 6, 2024 | In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image |
| CVE-2024-24942 | MEDIUM | 5.3 | 32.0% | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives |
| CVE-2024-24941 | MEDIUM | 5.3 | 0.3% | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an i... |
| CVE-2024-24940 | MEDIUM | 4.3 | 0.3% | Feb 6, 2024 | In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives |
| CVE-2024-24939 | MEDIUM | 5.3 | 0.3% | Feb 6, 2024 | In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now