2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29376 | MEDIUM | 6.4 | 0.4% | Apr 22, 2024 | Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book. |
| CVE-2024-31666 | CRITICAL | 9.8 | 1.7% | Apr 22, 2024 | An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon... |
| CVE-2024-28436 | MEDIUM | 6.1 | 0.6% | Apr 22, 2024 | Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DA... |
| CVE-2024-28699 | HIGH | 7.8 | 0.4% | Apr 22, 2024 | A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::cop... |
| CVE-2024-3645 | MEDIUM | 6.4 | 0.3% | Apr 22, 2024 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-32368 | HIGH | 7.3 | 0.3% | Apr 22, 2024 | Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local atta... |
| CVE-2024-27349 | CRITICAL | 9.1 | 1.0% | Apr 22, 2024 | Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: f... |
| CVE-2024-27348 | CRITICAL | 9.8 | 99.2% | Apr 22, 2024 | RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1... |
| CVE-2024-27347 | MEDIUM | 5.3 | 1.0% | Apr 22, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: ... |
| CVE-2024-4026 | MEDIUM | 4.6 | 0.3% | Apr 22, 2024 | Cross-Site Scripting (XSS) vulnerability in the Holded application. This vulnerability could allow an attacker to store ... |
| CVE-2024-29661 | CRITICAL | 9.8 | 0.7% | Apr 22, 2024 | A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload. |
| CVE-2024-28717 | MEDIUM | 4.9 | 0.9% | Apr 22, 2024 | An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component. |
| CVE-2024-22856 | MEDIUM | 5.4 | 0.3% | Apr 22, 2024 | A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows auth... |
| CVE-2024-22815 | MEDIUM | 5.3 | 0.2% | Apr 22, 2024 | An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cau... |
| CVE-2024-22813 | MEDIUM | 4.4 | 0.4% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP addres... |
| CVE-2024-22811 | HIGH | 8.2 | 0.4% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b... |
| CVE-2024-22809 | MEDIUM | 6.5 | 0.3% | Apr 22, 2024 | Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code... |
| CVE-2024-22808 | HIGH | 7.5 | 0.5% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) b... |
| CVE-2024-22807 | MEDIUM | 6.5 | 0.4% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the fl... |
| CVE-2024-32691 | MEDIUM | 5.3 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Produ... |
| CVE-2024-32688 | MEDIUM | 6.5 | 0.5% | Apr 22, 2024 | Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0. |
| CVE-2024-32687 | MEDIUM | 4.3 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Fr... |
| CVE-2024-32684 | HIGH | 7.5 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in Wpmet Wp Ultimate Review.This issue affects Wp Ultimate Review: from n/a through ... |
| CVE-2024-32682 | HIGH | 8.8 | 0.5% | Apr 22, 2024 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad... |
| CVE-2024-32681 | HIGH | 8.8 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now