2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2908 | MEDIUM | 4.3 | 0.7% | Apr 26, 2024 | The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-2837 | MEDIUM | 5.4 | 0.5% | Apr 26, 2024 | The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-2603 | MEDIUM | 6.3 | 0.5% | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-2439 | MEDIUM | 4.8 | 0.4% | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a... |
| CVE-2024-2429 | MEDIUM | 4.3 | 0.2% | Apr 26, 2024 | The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, wh... |
| CVE-2024-2310 | MEDIUM | 5.9 | 0.3% | Apr 26, 2024 | The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-2159 | MEDIUM | 4.7 | 0.5% | Apr 26, 2024 | The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes ... |
| CVE-2024-0905 | MEDIUM | 6.3 | 0.5% | Apr 26, 2024 | The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-3154 | HIGH | 7.2 | 1.4% | Apr 26, 2024 | A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can cr... |
| CVE-2024-32406 | HIGH | 7.5 | 1.1% | Apr 26, 2024 | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execut... |
| CVE-2024-32404 | MEDIUM | 6 | 0.8% | Apr 26, 2024 | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execut... |
| CVE-2024-22633 | CRITICAL | 9.8 | 0.9% | Apr 26, 2024 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (... |
| CVE-2024-22632 | CRITICAL | 9.8 | 1.0% | Apr 26, 2024 | Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (... |
| CVE-2024-4163 | HIGH | 8 | 0.4% | Apr 26, 2024 | The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovere... |
| CVE-2024-31755 | HIGH | 7.6 | 0.6% | Apr 26, 2024 | cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of func... |
| CVE-2024-33673 | HIGH | 7.8 | 0.2% | Apr 26, 2024 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacki... |
| CVE-2024-33672 | HIGH | 7.1 | 0.2% | Apr 26, 2024 | An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to... |
| CVE-2024-33671 | HIGH | 7.1 | 0.2% | Apr 26, 2024 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded S... |
| CVE-2024-33670 | MEDIUM | 4.3 | 0.5% | Apr 26, 2024 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a u... |
| CVE-2024-33669 | MEDIUM | 6.8 | 0.6% | Apr 26, 2024 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned whil... |
| CVE-2024-33668 | CRITICAL | 9.1 | 0.4% | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to id... |
| CVE-2024-33667 | MEDIUM | 6.5 | 0.6% | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack b... |
| CVE-2024-33666 | HIGH | 8.6 | 0.5% | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounti... |
| CVE-2024-33665 | MEDIUM | 6.1 | 0.5% | Apr 26, 2024 | angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor ... |
| CVE-2024-33664 | MEDIUM | 5.3 | 0.8% | Apr 26, 2024 | python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a cra... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now