2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36014 | MEDIUM | 5.5 | 0.2% | May 29, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/arm/malidp: fix a possible null pointer derefer... |
| CVE-2024-4419 | MEDIUM | 4 | 0.2% | May 29, 2024 | The Fetch JFT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
| CVE-2024-3937 | MEDIUM | 4.8 | 0.3% | May 29, 2024 | The Playlist for Youtube WordPress plugin through 1.32 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-3921 | MEDIUM | 4.8 | 0.4% | May 29, 2024 | The Gianism WordPress plugin through 5.1.0 does not sanitise and escape some of its settings, which could allow high pri... |
| CVE-2024-3050 | CRITICAL | 9.1 | 0.6% | May 29, 2024 | The Site Reviews WordPress plugin before 7.0.0 retrieves client IP addresses from potentially untrusted headers, allowin... |
| CVE-2024-4611 | HIGH | 8.1 | 0.5% | May 29, 2024 | The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_valu... |
| CVE-2024-21512 | HIGH | 8.2 | 3.1% | May 29, 2024 | Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitizatio... |
| CVE-2024-0434 | MEDIUM | 5.3 | 0.4% | May 29, 2024 | The WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2024-5204 | HIGH | 8.8 | 0.6% | May 29, 2024 | The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1... |
| CVE-2024-5150 | CRITICAL | 9.8 | 0.8% | May 29, 2024 | The Login with phone number plugin for WordPress is vulnerable to authentication bypass in versions up to, and including... |
| CVE-2024-5437 | MEDIUM | 6.1 | 0.4% | May 29, 2024 | A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as problematic. Aff... |
| CVE-2024-36112 | MEDIUM | 6.5 | 0.4% | May 28, 2024 | Nautobot is a Network Source of Truth and Network Automation Platform. A user with permissions to view Dynamic Group rec... |
| CVE-2024-23580 | MEDIUM | 6.5 | 0.1% | May 28, 2024 | HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of One-Time Passwords (OTPs). This could allow an at... |
| CVE-2024-23579 | MEDIUM | 6.5 | 0.1% | May 28, 2024 | HCL DRYiCE Optibot Reset Station is impacted by insecure encryption of security questions. This could allow an attacker ... |
| CVE-2024-35548 | MEDIUM | 5.4 | 0.4% | May 28, 2024 | A SQL injection vulnerability in Mybatis plus versions below 3.5.6 allows remote attackers to obtain database informatio... |
| CVE-2024-35511 | MEDIUM | 4.7 | 0.4% | May 28, 2024 | phpgurukul Men Salon Management System v2.0 is vulnerable to SQL Injection via the "username" parameter of /msms/admin/i... |
| CVE-2024-35240 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | Umbraco Commerce is an open source dotnet ecommerce solution. In affected versions there exists a stored Cross-site scri... |
| CVE-2024-35239 | MEDIUM | 5.4 | 0.3% | May 28, 2024 | Umbraco Commerce is an open source dotnet web forms solution. In affected versions an authenticated user that has access... |
| CVE-2024-35226 | HIGH | 7.3 | 0.5% | May 28, 2024 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In a... |
| CVE-2024-22641 | HIGH | 7.5 | 1.1% | May 28, 2024 | TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG... |
| CVE-2024-35583 | MEDIUM | 6.1 | 0.5% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-35582 | MEDIUM | 6.1 | 0.4% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-35581 | MEDIUM | 6.1 | 0.4% | May 28, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-35510 | CRITICAL | 9.8 | 0.7% | May 28, 2024 | An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute ... |
| CVE-2024-28061 | MEDIUM | 6.3 | 0.3% | May 28, 2024 | An issue was discovered in Apiris Kafeo 6.4.4. It permits a bypass, of the protection in place, to access to the data st... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now