2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2358 | CRITICAL | 9.8 | 1.1% | May 16, 2024 | A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute ar... |
| CVE-2024-20793 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis... |
| CVE-2024-20792 | HIGH | 7.8 | 0.4% | May 16, 2024 | Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitr... |
| CVE-2024-20791 | HIGH | 7.8 | 0.3% | May 16, 2024 | Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted... |
| CVE-2024-4966 | CRITICAL | 9.8 | 0.9% | May 16, 2024 | A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknow... |
| CVE-2024-4965 | CRITICAL | 9.8 | 2.9% | May 16, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000-40 V31R02B1413C and classified as critical.... |
| CVE-2024-4964 | CRITICAL | 9.8 | 2.5% | May 16, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DAR-7000-40 V31R02B1413C and classified as crit... |
| CVE-2024-4546 | MEDIUM | 6.4 | 0.3% | May 16, 2024 | The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_... |
| CVE-2024-4478 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Gro... |
| CVE-2024-4963 | CRITICAL | 9.8 | 3.0% | May 16, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DAR-7000-40 V31R0... |
| CVE-2024-4962 | CRITICAL | 9.8 | 2.5% | May 16, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DAR-7000-40 ... |
| CVE-2024-4844 | HIGH | 7.5 | 0.2% | May 16, 2024 | Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update... |
| CVE-2024-4961 | CRITICAL | 9.8 | 2.3% | May 16, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical was found in D-Link DAR-7000-40 V31R02B1413C. Aff... |
| CVE-2024-4960 | CRITICAL | 9.8 | 2.3% | May 16, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in D-Link DAR-7000-40 V31R02B1413C... |
| CVE-2024-4946 | HIGH | 8.8 | 0.7% | May 16, 2024 | A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. ... |
| CVE-2024-4843 | MEDIUM | 4.3 | 0.3% | May 16, 2024 | ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow... |
| CVE-2024-4635 | MEDIUM | 6.4 | 0.4% | May 16, 2024 | The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ fu... |
| CVE-2024-4318 | MEDIUM | 6.5 | 0.5% | May 16, 2024 | The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions... |
| CVE-2024-4279 | MEDIUM | 6.5 | 0.4% | May 16, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2024-3644 | MEDIUM | 4.8 | 0.4% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-3643 | HIGH | 8.8 | 0.4% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attacke... |
| CVE-2024-3642 | MEDIUM | 6.9 | 0.3% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow a... |
| CVE-2024-3641 | MEDIUM | 6.1 | 0.4% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauth... |
| CVE-2024-4945 | CRITICAL | 9.8 | 0.9% | May 16, 2024 | A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as problematic. A... |
| CVE-2024-4933 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability has been found in SourceCodester Simple Online Bidding System 1.0 and classified as critical. Affected b... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now