2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32679 | MEDIUM | 5.3 | 0.4% | Apr 23, 2024 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a... |
| CVE-2024-31804 | MEDIUM | 6.7 | 0.7% | Apr 23, 2024 | An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privile... |
| CVE-2024-28130 | HIGH | 7.5 | 1.7% | Apr 23, 2024 | An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS D... |
| CVE-2024-2477 | MEDIUM | 5.4 | 0.3% | Apr 23, 2024 | The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an up... |
| CVE-2024-28627 | HIGH | 7.5 | 0.4% | Apr 23, 2024 | An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file. |
| CVE-2024-3911 | MEDIUM | 6.5 | 0.5% | Apr 23, 2024 | An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of r... |
| CVE-2024-30800 | MEDIUM | 5.6 | 0.2% | Apr 23, 2024 | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the ... |
| CVE-2024-26922 | MEDIUM | 5.5 | 0.3% | Apr 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o... |
| CVE-2024-3491 | MEDIUM | 6.4 | 0.3% | Apr 23, 2024 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-3732 | MEDIUM | 5.4 | 0.3% | Apr 23, 2024 | The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to St... |
| CVE-2024-3665 | MEDIUM | 5.4 | 0.5% | Apr 23, 2024 | The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's H... |
| CVE-2024-3185 | MEDIUM | 6.8 | 0.2% | Apr 23, 2024 | A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in th... |
| CVE-2024-0900 | MEDIUM | 4.3 | 0.4% | Apr 23, 2024 | The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding... |
| CVE-2024-3664 | MEDIUM | 4.3 | 0.3% | Apr 23, 2024 | The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2024-4031 | MEDIUM | 4.4 | 0.2% | Apr 23, 2024 | Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code. |
| CVE-2024-3889 | MEDIUM | 6.4 | 0.3% | Apr 23, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-2799 | MEDIUM | 6.4 | 0.4% | Apr 23, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image... |
| CVE-2024-2798 | MEDIUM | 6.4 | 0.3% | Apr 23, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-2493 | HIGH | 7.5 | 0.3% | Apr 23, 2024 | Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0... |
| CVE-2024-31857 | MEDIUM | 5.4 | 0.6% | Apr 23, 2024 | Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote a... |
| CVE-2024-31077 | HIGH | 7.2 | 30.4% | Apr 23, 2024 | Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenti... |
| CVE-2024-28890 | MEDIUM | 5.3 | 0.7% | Apr 23, 2024 | Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerabil... |
| CVE-2024-21511 | CRITICAL | 9.8 | 1.0% | Apr 23, 2024 | Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of t... |
| CVE-2024-2760 | MEDIUM | 5.5 | 0.2% | Apr 23, 2024 | Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IO... |
| CVE-2024-1241 | MEDIUM | 5.5 | 0.2% | Apr 23, 2024 | Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now