2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29960 | HIGH | 7.5 | 0.3% | Apr 19, 2024 | In Brocade SANnav server before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are identical in the VM every tim... |
| CVE-2024-29959 | HIGH | 8.6 | 0.5% | Apr 19, 2024 | A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the B... |
| CVE-2024-29958 | MEDIUM | 6.5 | 0.3% | Apr 19, 2024 | A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged u... |
| CVE-2024-29957 | HIGH | 7.5 | 0.3% | Apr 19, 2024 | When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is st... |
| CVE-2024-3818 | MEDIUM | 5.4 | 0.3% | Apr 19, 2024 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-3731 | MEDIUM | 6.1 | 0.4% | Apr 19, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' pa... |
| CVE-2024-3615 | MEDIUM | 6.1 | 0.4% | Apr 19, 2024 | The Media Library Folders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in ... |
| CVE-2024-3600 | MEDIUM | 6.1 | 0.4% | Apr 19, 2024 | The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a m... |
| CVE-2024-3598 | MEDIUM | 5.4 | 0.3% | Apr 19, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button w... |
| CVE-2024-3560 | MEDIUM | 5.4 | 0.3% | Apr 19, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id valu... |
| CVE-2024-29204 | CRITICAL | 9.8 | 4.3% | Apr 19, 2024 | A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthent... |
| CVE-2024-27984 | HIGH | 7.1 | 1.8% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-27978 | MEDIUM | 6.5 | 1.7% | Apr 19, 2024 | A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth... |
| CVE-2024-27977 | HIGH | 8.1 | 1.8% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-27976 | HIGH | 8.8 | 3.2% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-27975 | HIGH | 8.8 | 2.6% | Apr 19, 2024 | An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authent... |
| CVE-2024-25000 | HIGH | 8.8 | 3.0% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24999 | HIGH | 8.8 | 2.9% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24998 | HIGH | 8.8 | 3.2% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24997 | HIGH | 8.8 | 3.2% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24996 | CRITICAL | 9.8 | 32.2% | Apr 19, 2024 | A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated ... |
| CVE-2024-24995 | HIGH | 7.5 | 2.4% | Apr 19, 2024 | A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated ... |
| CVE-2024-24994 | HIGH | 8.8 | 68.1% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
| CVE-2024-24993 | HIGH | 7.5 | 2.4% | Apr 19, 2024 | A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated ... |
| CVE-2024-24992 | HIGH | 8.8 | 70.9% | Apr 19, 2024 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now