2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3372 | HIGH | 7.5 | 0.6% | May 14, 2024 | Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be perfo... |
| CVE-2024-3241 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputt... |
| CVE-2024-35012 | MEDIUM | 6.3 | 0.2% | May 14, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu... |
| CVE-2024-35011 | MEDIUM | 5.4 | 0.2% | May 14, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu... |
| CVE-2024-35010 | HIGH | 8.8 | 0.3% | May 14, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/banner_deal.php?mudi... |
| CVE-2024-35009 | HIGH | 8.8 | 0.3% | May 14, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/share_switch.php?mud... |
| CVE-2024-34950 | HIGH | 7.5 | 5.2% | May 14, 2024 | D-Link DIR-822+ v1.0.5 was discovered to contain a stack-based buffer overflow vulnerability in the SetNetworkTomography... |
| CVE-2024-34914 | MEDIUM | 5.3 | 0.3% | May 14, 2024 | php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. Th... |
| CVE-2024-34773 | HIGH | 7.8 | 0.3% | May 14, 2024 | A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected applications contain a ... |
| CVE-2024-34772 | HIGH | 7.8 | 0.3% | May 14, 2024 | A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 4). The affected applications contain an... |
| CVE-2024-34771 | HIGH | 7.8 | 0.3% | May 14, 2024 | A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected application is vulnerab... |
| CVE-2024-34717 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-o... |
| CVE-2024-34716 | MEDIUM | 6.1 | 56.2% | May 14, 2024 | PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects Pr... |
| CVE-2024-34714 | HIGH | 7.6 | 0.3% | May 14, 2024 | The Hoppscotch Browser Extension is a browser extension for Hoppscotch, a community-driven end-to-end open-source API de... |
| CVE-2024-34713 | LOW | 3.5 | 0.4% | May 14, 2024 | sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. P... |
| CVE-2024-34712 | MEDIUM | 6.5 | 0.6% | May 14, 2024 | Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.re... |
| CVE-2024-34687 | CRITICAL | 9 | 0.4% | May 14, 2024 | SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting... |
| CVE-2024-34358 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E... |
| CVE-2024-34357 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E... |
| CVE-2024-34356 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E... |
| CVE-2024-34355 | MEDIUM | 5.4 | 0.6% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history ba... |
| CVE-2024-34256 | CRITICAL | 9.8 | 0.7% | May 14, 2024 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. |
| CVE-2024-34243 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter. |
| CVE-2024-34191 | MEDIUM | 6.5 | 0.5% | May 14, 2024 | htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.... |
| CVE-2024-34086 | HIGH | 7.8 | 0.2% | May 14, 2024 | A vulnerability has been identified in JT2Go (All versions < V2312.0001), Teamcenter Visualization V14.1 (All versions <... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now