2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34488 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via ... |
| CVE-2024-34487 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.... |
| CVE-2024-34486 | HIGH | 7.5 | 0.6% | May 5, 2024 | OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFP... |
| CVE-2024-34484 | MEDIUM | 5.3 | 0.5% | May 5, 2024 | OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.l... |
| CVE-2024-34483 | HIGH | 7.5 | 0.7% | May 5, 2024 | OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via ... |
| CVE-2024-4492 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the fu... |
| CVE-2024-34478 | HIGH | 7.5 | 0.6% | May 5, 2024 | btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptibl... |
| CVE-2024-4491 | HIGH | 8.8 | 1.5% | May 5, 2024 | A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function fo... |
| CVE-2024-34476 | MEDIUM | 5.3 | 0.5% | May 5, 2024 | Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_... |
| CVE-2024-34475 | HIGH | 7.5 | 0.6% | May 5, 2024 | Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_... |
| CVE-2024-34473 | MEDIUM | 5.3 | 0.4% | May 4, 2024 | An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message t... |
| CVE-2024-34469 | HIGH | 7.1 | 0.6% | May 4, 2024 | Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save. |
| CVE-2024-34468 | MEDIUM | 6.1 | 0.3% | May 4, 2024 | Rukovoditel before 3.5.3 allows XSS via user_photo to My Page. |
| CVE-2024-34467 | MEDIUM | 6.1 | 0.4% | May 4, 2024 | ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_e... |
| CVE-2024-34462 | MEDIUM | 6.1 | 0.3% | May 4, 2024 | Alinto SOGo through 5.10.0 allows XSS during attachment preview. |
| CVE-2024-1050 | MEDIUM | 4.3 | 0.4% | May 4, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2024-34461 | CRITICAL | 9.8 | 1.0% | May 4, 2024 | Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY ele... |
| CVE-2024-34460 | MEDIUM | 6.5 | 0.6% | May 4, 2024 | The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5... |
| CVE-2024-3240 | HIGH | 8.8 | 0.8% | May 4, 2024 | The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 ... |
| CVE-2024-3237 | MEDIUM | 5.4 | 0.4% | May 4, 2024 | The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2024-3868 | MEDIUM | 5.4 | 0.4% | May 4, 2024 | The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name ... |
| CVE-2024-34455 | HIGH | 7.5 | 0.7% | May 3, 2024 | Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2. |
| CVE-2024-34453 | MEDIUM | 4.3 | 0.3% | May 3, 2024 | TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity... |
| CVE-2024-34075 | MEDIUM | 6.2 | 0.3% | May 3, 2024 | kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the ... |
| CVE-2024-34068 | MEDIUM | 6.4 | 0.4% | May 3, 2024 | Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game serv... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now