2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34707 | MEDIUM | 4.8 | 0.6% | May 14, 2024 | Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify ... |
| CVE-2024-34706 | CRITICAL | 9.8 | 1.1% | May 14, 2024 | Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access toke... |
| CVE-2024-34704 | MEDIUM | 5.9 | 0.5% | May 14, 2024 | era-compiler-solidity is the ZKsync compiler for Solidity. The problem occurred during instruction selection in the `DA... |
| CVE-2024-34701 | MEDIUM | 5.9 | 0.6% | May 14, 2024 | CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users to be considered ... |
| CVE-2024-34699 | MEDIUM | 6.5 | 0.5% | May 14, 2024 | GZ::CTF is a capture the flag platform. Prior to 0.20.1, unprivileged user can perform cross-site scripting attacks on o... |
| CVE-2024-34698 | MEDIUM | 6.3 | 0.5% | May 14, 2024 | FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototyp... |
| CVE-2024-34697 | MEDIUM | 6.1 | 0.6% | May 14, 2024 | FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified... |
| CVE-2024-34695 | MEDIUM | 6.3 | 0.8% | May 14, 2024 | WOWS Karma is a reputation system for Wargaming's World of Warships. A user is able to click multiple times on "create" ... |
| CVE-2024-34559 | HIGH | 7.5 | 0.7% | May 14, 2024 | Insertion of Sensitive Information into Log File vulnerability in Ghost Foundation Ghost.This issue affects Ghost: from ... |
| CVE-2024-34557 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Or... |
| CVE-2024-34556 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner wit... |
| CVE-2024-34555 | CRITICAL | 10 | 1.2% | May 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: ... |
| CVE-2024-34550 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Insertion of Sensitive Information into Log File vulnerability in AlexaCRM Dynamics 365 Integration.This issue affects D... |
| CVE-2024-34549 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic WP Job Manager.This issue affects... |
| CVE-2024-34459 | HIGH | 7.5 | 2.3% | May 14, 2024 | An issue was discovered in xmllint (from libxml2) before 2.11.8 and 2.12.x before 2.12.7. Formatting error messages with... |
| CVE-2024-34445 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Add... |
| CVE-2024-34441 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bootstrapped Ventu... |
| CVE-2024-34440 | HIGH | 7.2 | 0.8% | May 14, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affect... |
| CVE-2024-34439 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in divSpot DS Site Message.This issue affects DS Site Message: from n/a ... |
| CVE-2024-34437 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Form Builder... |
| CVE-2024-34436 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SKT Themes SKT Add... |
| CVE-2024-34433 | HIGH | 7.2 | 0.5% | May 14, 2024 | Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects One Click Demo Import: ... |
| CVE-2024-34432 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BetterAddons Bette... |
| CVE-2024-34431 | HIGH | 7.1 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etr... |
| CVE-2024-34430 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rashed Latif TT Cu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now