2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27109 | HIGH | 7.6 | 0.3% | May 14, 2024 | Insufficiently protected credentials in GE HealthCare EchoPAC products |
| CVE-2024-27108 | MEDIUM | 6.8 | 0.3% | May 14, 2024 | Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products |
| CVE-2024-27107 | CRITICAL | 9.6 | 0.3% | May 14, 2024 | Weak account password in GE HealthCare EchoPAC products |
| CVE-2024-27106 | MEDIUM | 5.7 | 0.2% | May 14, 2024 | Vulnerable data in transit in GE HealthCare EchoPAC products |
| CVE-2024-26238 | HIGH | 7.8 | 0.7% | May 14, 2024 | Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability |
| CVE-2024-26007 | HIGH | 7.5 | 1.2% | May 14, 2024 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows... |
| CVE-2024-23105 | HIGH | 7.5 | 0.4% | May 14, 2024 | A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2... |
| CVE-2024-1630 | HIGH | 7.7 | 0.3% | May 14, 2024 | Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound de... |
| CVE-2024-1629 | MEDIUM | 6.2 | 0.3% | May 14, 2024 | Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device comp... |
| CVE-2024-4871 | MEDIUM | 6.8 | 0.6% | May 14, 2024 | A vulnerability was found in Satellite. When running a remote execution job on a host, the host's SSH key is not being c... |
| CVE-2024-4860 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerab... |
| CVE-2024-4859 | MEDIUM | 5.7 | 0.4% | May 14, 2024 | Solidus <= 4.3.4 is affected by a Stored Cross-Site Scripting vulnerability in the order tracking URL. |
| CVE-2024-4810 | — | — | — | May 14, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. This CVE has been replaced b... |
| CVE-2024-4761 | HIGH | 8.8 | 11.0% | May 14, 2024 | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds... |
| CVE-2024-4624 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugins for WordPres... |
| CVE-2024-4473 | MEDIUM | 5.4 | 0.3% | May 14, 2024 | The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "aThemes: Portfolio" widget... |
| CVE-2024-4445 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2024-4440 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The 140+ Widgets | Best Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-4392 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-4333 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-4144 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all v... |
| CVE-2024-4139 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu... |
| CVE-2024-4138 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu... |
| CVE-2024-3579 | MEDIUM | 6.1 | 0.3% | May 14, 2024 | Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker m... |
| CVE-2024-3374 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to atte... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now