2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27129 | HIGH | 8.8 | 0.7% | May 21, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-27128 | HIGH | 8.8 | 0.7% | May 21, 2024 | A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system ver... |
| CVE-2024-27127 | HIGH | 8.8 | 0.7% | May 21, 2024 | A double free vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulner... |
| CVE-2024-21902 | HIGH | 8.1 | 0.4% | May 21, 2024 | An incorrect permission assignment for critical resource vulnerability has been reported to affect several QNAP operatin... |
| CVE-2024-1721 | MEDIUM | 5.6 | 0.1% | May 21, 2024 | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software... |
| CVE-2024-33529 | HIGH | 7.2 | 0.9% | May 21, 2024 | ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrativ... |
| CVE-2024-33528 | MEDIUM | 4.7 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authentic... |
| CVE-2024-33527 | MEDIUM | 5.4 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 bef... |
| CVE-2024-33526 | HIGH | 7.1 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user role" feature in ILIAS 7... |
| CVE-2024-4452 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in version... |
| CVE-2024-35386 | HIGH | 7.5 | 0.6% | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_do_gc function in the m... |
| CVE-2024-35385 | MEDIUM | 4.3 | 0.5% | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in ... |
| CVE-2024-35384 | MEDIUM | 5.5 | 0.3% | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function i... |
| CVE-2024-35218 | MEDIUM | 4.8 | 0.4% | May 21, 2024 | Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers tha... |
| CVE-2024-34071 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirec... |
| CVE-2024-35361 | CRITICAL | 9.8 | 0.5% | May 21, 2024 | MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL sta... |
| CVE-2024-35180 | MEDIUM | 6.1 | 0.3% | May 21, 2024 | OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `ca... |
| CVE-2024-4420 | HIGH | 7.5 | 0.2% | May 21, 2024 | There exists a Denial of service vulnerability in Tink-cc in versions prior to 2.1.3. * An adversary can crash binari... |
| CVE-2024-3268 | MEDIUM | 5.3 | 0.3% | May 21, 2024 | The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to... |
| CVE-2024-4876 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p... |
| CVE-2024-4619 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cro... |
| CVE-2024-4361 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteo... |
| CVE-2024-4988 | HIGH | 7.5 | 0.4% | May 21, 2024 | The mobile application (com.transsion.videocallenhancer) interface has improper permission control, which can lead to th... |
| CVE-2024-4700 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-4695 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now