2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4248 | HIGH | 8.8 | 1.3% | Apr 27, 2024 | A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. This issue affects the function formQo... |
| CVE-2024-4247 | HIGH | 8.8 | 1.5% | Apr 27, 2024 | A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. This vulnerability affects the fu... |
| CVE-2024-3309 | MEDIUM | 5.4 | 0.3% | Apr 27, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's... |
| CVE-2024-4246 | HIGH | 8.8 | 1.3% | Apr 27, 2024 | A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). This affects the function form... |
| CVE-2024-3342 | CRITICAL | 9.9 | 0.6% | Apr 27, 2024 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri... |
| CVE-2024-4245 | HIGH | 8.8 | 1.3% | Apr 27, 2024 | A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is... |
| CVE-2024-3034 | LOW | 2.7 | 0.7% | Apr 27, 2024 | The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13... |
| CVE-2024-2838 | MEDIUM | 6.4 | 0.3% | Apr 27, 2024 | The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo... |
| CVE-2024-2258 | MEDIUM | 5.4 | 0.4% | Apr 27, 2024 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-2859 | HIGH | 7.2 | 0.8% | Apr 27, 2024 | By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could exp... |
| CVE-2024-4244 | HIGH | 8.8 | 1.3% | Apr 26, 2024 | A vulnerability classified as critical was found in Tenda W9 1.0.0.7(4456). Affected by this vulnerability is the functi... |
| CVE-2024-4243 | HIGH | 8.8 | 1.3% | Apr 26, 2024 | A vulnerability classified as critical has been found in Tenda W9 1.0.0.7(4456). Affected is the function formwrlSSIDset... |
| CVE-2024-3052 | HIGH | 7.5 | 0.5% | Apr 26, 2024 | Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway... |
| CVE-2024-3051 | HIGH | 7.5 | 0.5% | Apr 26, 2024 | Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent... |
| CVE-2024-31828 | MEDIUM | 6.1 | 0.5% | Apr 26, 2024 | Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensit... |
| CVE-2024-31741 | MEDIUM | 6.1 | 0.4% | Apr 26, 2024 | Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string i... |
| CVE-2024-31551 | HIGH | 7.5 | 0.7% | Apr 26, 2024 | Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete a... |
| CVE-2024-30804 | CRITICAL | 9.8 | 0.8% | Apr 26, 2024 | An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbi... |
| CVE-2024-28322 | CRITICAL | 9.8 | 0.8% | Apr 26, 2024 | SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allo... |
| CVE-2024-4242 | HIGH | 8.8 | 1.3% | Apr 26, 2024 | A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function form... |
| CVE-2024-4241 | HIGH | 8.8 | 1.3% | Apr 26, 2024 | A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the fu... |
| CVE-2024-4240 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQ... |
| CVE-2024-4239 | HIGH | 8.8 | 1.5% | Apr 26, 2024 | A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function for... |
| CVE-2024-32887 | MEDIUM | 5.5 | 0.6% | Apr 26, 2024 | Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr... |
| CVE-2024-32883 | HIGH | 7.7 | 0.1% | Apr 26, 2024 | MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now