LiveActive security incident?Get immediate response
CVE archive

February 2024

Browse CVE records published in February 2024, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2872 matching CVEs · Page 1 of 58.

Medium · CVSS 5.4

CVE-2024-11831: Npm-serialize-javascript: cross-site scripting (xss) in serialize-javascript

A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.

Published Feb 10, 2025 · Updated Aug 23, 2026

High · CVSS 7.7

CVE-2024-0410: Improper Enforcement of Behavioral Workflow in GitLab

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

Published Feb 21, 2024 · Updated Aug 14, 2026