2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35099 | CRITICAL | 9.8 | 0.8% | May 14, 2024 | TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the funct... |
| CVE-2024-35050 | HIGH | 8.8 | 0.7% | May 14, 2024 | An issue in SurveyKing v1.3.1 allows attackers to escalate privileges via re-using the session ID of a user that was del... |
| CVE-2024-35049 | CRITICAL | 9.1 | 0.7% | May 14, 2024 | SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-... |
| CVE-2024-35048 | MEDIUM | 4.3 | 0.4% | May 14, 2024 | An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password. |
| CVE-2024-34974 | HIGH | 8.2 | 0.7% | May 14, 2024 | Tenda AC18 v15.03.05.19 is vulnerable to Buffer Overflow in the formSetPPTPServer function via the endIp parameter. |
| CVE-2024-34946 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parame... |
| CVE-2024-34945 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW paramet... |
| CVE-2024-34944 | HIGH | 8.8 | 0.4% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the list1 param... |
| CVE-2024-34943 | CRITICAL | 9.8 | 0.9% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parame... |
| CVE-2024-34942 | HIGH | 8.8 | 0.9% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 p... |
| CVE-2024-34921 | HIGH | 8.8 | 9.3% | May 14, 2024 | TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function. |
| CVE-2024-34899 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2024-34828 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin:... |
| CVE-2024-34827 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban Tra... |
| CVE-2024-34825 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: fro... |
| CVE-2024-34823 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects A... |
| CVE-2024-34818 | HIGH | 7.1 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress.This issue affects WebinarPress: from n/a through 1.33.1... |
| CVE-2024-34817 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elem... |
| CVE-2024-34816 | MEDIUM | 5.4 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io... |
| CVE-2024-34814 | MEDIUM | 5.4 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2... |
| CVE-2024-34812 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Build... |
| CVE-2024-34811 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ... |
| CVE-2024-34749 | MEDIUM | 6.1 | 0.7% | May 14, 2024 | Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remot... |
| CVE-2024-34709 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens functi... |
| CVE-2024-34708 | MEDIUM | 4.9 | 0.8% | May 14, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any coll... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now