2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33121 | MEDIUM | 6.3 | 0.3% | May 6, 2024 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. |
| CVE-2024-33118 | HIGH | 7.5 | 0.2% | May 6, 2024 | LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.... |
| CVE-2024-33117 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.z... |
| CVE-2024-3661 | HIGH | 7.6 | 4.1% | May 6, 2024 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solution... |
| CVE-2024-34412 | HIGH | 8.5 | 0.5% | May 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel Parce... |
| CVE-2024-34390 | MEDIUM | 6.5 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post G... |
| CVE-2024-34389 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.... |
| CVE-2024-34387 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.... |
| CVE-2024-34386 | HIGH | 7.6 | 0.5% | May 6, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Aut... |
| CVE-2024-34381 | MEDIUM | 5.4 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allow... |
| CVE-2024-34380 | MEDIUM | 6.5 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conve... |
| CVE-2024-34379 | MEDIUM | 4.3 | 0.2% | May 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe... |
| CVE-2024-34378 | HIGH | 8.6 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7. |
| CVE-2024-34377 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue... |
| CVE-2024-34376 | MEDIUM | 6.5 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge... |
| CVE-2024-34375 | MEDIUM | 5.9 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To W... |
| CVE-2024-34374 | MEDIUM | 5.4 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft Elemen... |
| CVE-2024-34373 | MEDIUM | 5.4 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus ... |
| CVE-2024-34372 | MEDIUM | 5.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a throug... |
| CVE-2024-34371 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L... |
| CVE-2024-34369 | HIGH | 7.1 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push ... |
| CVE-2024-34368 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mooberry Dreams Mooberry Book Manager.This i... |
| CVE-2024-34367 | HIGH | 7.1 | 0.2% | May 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue... |
| CVE-2024-34366 | MEDIUM | 5.9 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Downloa... |
| CVE-2024-33912 | HIGH | 8.8 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now