2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21866 | MEDIUM | 5.3 | 0.4% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error me... |
| CVE-2024-21794 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages t... |
| CVE-2024-23034 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary c... |
| CVE-2024-23033 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary co... |
| CVE-2024-23032 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code vi... |
| CVE-2024-23031 | MEDIUM | 6.1 | 0.4% | Feb 1, 2024 | Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr... |
| CVE-2024-22927 | MEDIUM | 6.1 | 1.0% | Feb 1, 2024 | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr... |
| CVE-2024-24755 | MEDIUM | 5.3 | 0.4% | Feb 1, 2024 | discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP... |
| CVE-2024-1040 | MEDIUM | 4.4 | 0.1% | Feb 1, 2024 | Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by... |
| CVE-2024-24945 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att... |
| CVE-2024-24041 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows att... |
| CVE-2024-24569 | MEDIUM | 4.8 | 0.6% | Feb 1, 2024 | The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurre... |
| CVE-2024-23645 | MEDIUM | 6.1 | 0.9% | Feb 1, 2024 | GLPI is a Free Asset and IT Management Software package. A malicious URL can be used to execute XSS on reports pages. U... |
| CVE-2024-24570 | MEDIUM | 6.1 | 0.7% | Feb 1, 2024 | Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing f... |
| CVE-2024-24753 | MEDIUM | 6.5 | 0.4% | Feb 1, 2024 | Bref enable serverless PHP on AWS Lambda. When Bref is used in combination with an API Gateway with the v2 format, it do... |
| CVE-2024-24752 | MEDIUM | 6.5 | 0.8% | Feb 1, 2024 | Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a ... |
| CVE-2024-1141 | MEDIUM | 5.5 | 0.2% | Feb 1, 2024 | A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-s... |
| CVE-2024-24062 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/role. |
| CVE-2024-24061 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sysContent/add. |
| CVE-2024-24060 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Cross Site Scripting (XSS) via /sys/user. |
| CVE-2024-24059 | MEDIUM | 5.4 | 0.4% | Feb 1, 2024 | springboot-manager v1.6 is vulnerable to Arbitrary File Upload. The system does not filter the suffixes of uploaded file... |
| CVE-2024-22430 | MEDIUM | 5.5 | 0.1% | Feb 1, 2024 | Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local l... |
| CVE-2024-22148 | MEDIUM | 6.1 | 0.4% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Smart Editor Jo... |
| CVE-2024-21750 | MEDIUM | 6.1 | 0.4% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes... |
| CVE-2024-24548 | MEDIUM | 6.5 | 0.6% | Feb 1, 2024 | Payment EX Ver1.1.5b and earlier allows a remote unauthenticated attacker to obtain the information of the user who purc... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now