2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28716 | HIGH | 7.5 | 1.4% | Apr 30, 2024 | An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component. |
| CVE-2024-25938 | HIGH | 8.8 | 15.6% | Apr 30, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Barcode widget. A specially craft... |
| CVE-2024-25648 | HIGH | 8.8 | 15.6% | Apr 30, 2024 | A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a ComboBox widget. A specially craf... |
| CVE-2024-25575 | HIGH | 8.8 | 17.7% | Apr 30, 2024 | A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A spec... |
| CVE-2024-23774 | HIGH | 7.8 | 0.4% | Apr 30, 2024 | An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerabi... |
| CVE-2024-23773 | HIGH | 7.8 | 0.4% | Apr 30, 2024 | An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability ex... |
| CVE-2024-23772 | MEDIUM | 6.6 | 0.3% | Apr 30, 2024 | An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability ex... |
| CVE-2024-2617 | HIGH | 7.2 | 0.7% | Apr 30, 2024 | A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if se... |
| CVE-2024-2378 | HIGH | 8 | 0.2% | Apr 30, 2024 | A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privil... |
| CVE-2024-2377 | HIGH | 7.6 | 0.2% | Apr 30, 2024 | A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can tak... |
| CVE-2024-4337 | HIGH | 7.4 | 0.4% | Apr 30, 2024 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti... |
| CVE-2024-4336 | HIGH | 7.4 | 0.4% | Apr 30, 2024 | Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripti... |
| CVE-2024-22405 | MEDIUM | 5.5 | 0.2% | Apr 30, 2024 | XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted... |
| CVE-2024-4185 | HIGH | 8.1 | 0.9% | Apr 30, 2024 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authenticat... |
| CVE-2024-3072 | MEDIUM | 4.3 | 0.3% | Apr 30, 2024 | The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-2663 | HIGH | 8.3 | 0.4% | Apr 30, 2024 | The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i... |
| CVE-2024-1895 | HIGH | 7.5 | 0.9% | Apr 30, 2024 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object I... |
| CVE-2024-4225 | HIGH | 7.6 | 0.3% | Apr 30, 2024 | Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), b... |
| CVE-2024-31837 | HIGH | 8.4 | 0.2% | Apr 30, 2024 | DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE... |
| CVE-2024-1371 | MEDIUM | 6.5 | 0.6% | Apr 30, 2024 | The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capabi... |
| CVE-2024-4226 | LOW | 3.5 | 0.3% | Apr 30, 2024 | It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all use... |
| CVE-2024-0216 | MEDIUM | 6.4 | 0.3% | Apr 30, 2024 | The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in v... |
| CVE-2024-4327 | LOW | 3.5 | 0.5% | Apr 30, 2024 | A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unkno... |
| CVE-2024-34050 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<... |
| CVE-2024-34049 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now