2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3063 | MEDIUM | 5.4 | 0.2% | May 30, 2024 | The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' adde... |
| CVE-2024-2253 | MEDIUM | 6.4 | 0.3% | May 30, 2024 | The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values ... |
| CVE-2024-5514 | CRITICAL | 9.8 | 0.7% | May 30, 2024 | MinMax CMS from MinMax Digital Technology contains a hidden administrator account with a fixed password that cannot be r... |
| CVE-2024-3726 | MEDIUM | 6.4 | 0.3% | May 30, 2024 | The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrml... |
| CVE-2024-36114 | HIGH | 8.6 | 0.5% | May 29, 2024 | Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to Java. All decompr... |
| CVE-2024-35221 | MEDIUM | 4.3 | 0.5% | May 29, 2024 | Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. ... |
| CVE-2024-35492 | HIGH | 7.5 | 0.5% | May 29, 2024 | Cesanta Mongoose commit b316989 was discovered to contain a NULL pointer dereference via the scpy function at src/fmt.c.... |
| CVE-2024-36016 | HIGH | 7.8 | 0.3% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: fix possible out-of-bounds in gsm0_rece... |
| CVE-2024-35434 | HIGH | 7.5 | 0.6% | May 29, 2024 | Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/... |
| CVE-2024-35512 | MEDIUM | 5.3 | 0.5% | May 29, 2024 | hmq v1.5.5 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can trigger a bro... |
| CVE-2024-34715 | LOW | 3.3 | 0.3% | May 29, 2024 | Fides is an open-source privacy engineering platform. The Fides webserver requires a connection to a hosted PostgreSQL d... |
| CVE-2024-36427 | HIGH | 8.1 | 0.5% | May 29, 2024 | The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authent... |
| CVE-2024-35333 | HIGH | 8.4 | 0.4% | May 29, 2024 | A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occ... |
| CVE-2024-35311 | LOW | 3.3 | 0.2% | May 29, 2024 | Yubico YubiKey 5 Series before 5.7.0, Security Key Series before 5.7.0, YubiKey Bio Series before 5.6.4, and YubiKey 5 F... |
| CVE-2024-35284 | MEDIUM | 5.4 | 0.3% | May 29, 2024 | A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthen... |
| CVE-2024-35283 | MEDIUM | 6.1 | 0.3% | May 29, 2024 | A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticat... |
| CVE-2024-35200 | MEDIUM | 5.3 | 0.9% | May 29, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX w... |
| CVE-2024-34161 | MEDIUM | 5.3 | 0.9% | May 29, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maxi... |
| CVE-2024-32760 | MEDIUM | 6.5 | 0.8% | May 29, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can c... |
| CVE-2024-31079 | MEDIUM | 4.8 | 0.9% | May 29, 2024 | When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX w... |
| CVE-2024-28974 | MEDIUM | 6.5 | 0.1% | May 29, 2024 | Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privile... |
| CVE-2024-4358 | CRITICAL | 9.8 | 97.5% | May 29, 2024 | In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gai... |
| CVE-2024-36470 | CRITICAL | 9.8 | 0.5% | May 29, 2024 | In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific e... |
| CVE-2024-36378 | HIGH | 7.5 | 0.4% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 server was susceptible to DoS attacks with incorrect auth tokens |
| CVE-2024-36377 | HIGH | 8.1 | 0.3% | May 29, 2024 | In JetBrains TeamCity before 2024.03.2 certain TeamCity API endpoints did not check user permissions |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now