2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4661 | MEDIUM | 4.3 | 0.3% | Jun 8, 2024 | The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2024-5770 | MEDIUM | 4.3 | 0.3% | Jun 8, 2024 | The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2024-3668 | HIGH | 8.8 | 0.4% | Jun 8, 2024 | The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and in... |
| CVE-2024-5663 | MEDIUM | 5.4 | 0.3% | Jun 8, 2024 | The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cards wi... |
| CVE-2024-0444 | HIGH | 8.8 | 1.6% | Jun 7, 2024 | GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows r... |
| CVE-2024-1694 | HIGH | 7.8 | 0.1% | Jun 7, 2024 | Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass d... |
| CVE-2024-5761 | — | — | — | Jun 7, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2024-5260]. Reason: This candidate is a... |
| CVE-2024-3133 | — | — | — | Jun 7, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-37388 | CRITICAL | 9.1 | 0.5% | Jun 7, 2024 | An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers... |
| CVE-2024-36827 | HIGH | 7.5 | 0.5% | Jun 7, 2024 | An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows atta... |
| CVE-2024-36811 | — | — | — | Jun 7, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-37295. Reason: This candidate is a reservation d... |
| CVE-2024-23595 | — | — | — | Jun 7, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-5745 | CRITICAL | 9.8 | 0.9% | Jun 7, 2024 | A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affecte... |
| CVE-2024-4152 | — | — | — | Jun 7, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-3380 | — | — | — | Jun 7, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-37163 | HIGH | 7.5 | 0.2% | Jun 7, 2024 | SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests ar... |
| CVE-2024-32502 | HIGH | 8.4 | 0.2% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ... |
| CVE-2024-31959 | HIGH | 7.8 | 0.2% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the vali... |
| CVE-2024-31958 | HIGH | 7.8 | 0.1% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the val... |
| CVE-2024-30163 | CRITICAL | 9.8 | 8.7% | Jun 7, 2024 | Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\... |
| CVE-2024-30162 | HIGH | 7.2 | 0.7% | Jun 7, 2024 | Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.ph... |
| CVE-2024-32503 | HIGH | 7.8 | 0.2% | Jun 7, 2024 | An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ... |
| CVE-2024-37162 | MEDIUM | 5.3 | 0.3% | Jun 7, 2024 | zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers ... |
| CVE-2024-36792 | HIGH | 8.2 | 0.3% | Jun 7, 2024 | An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain acce... |
| CVE-2024-36790 | HIGH | 8.8 | 0.3% | Jun 7, 2024 | Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now