2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1755 | HIGH | 8.8 | 0.4% | Apr 15, 2024 | The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2024-1754 | MEDIUM | 4.7 | 0.5% | Apr 15, 2024 | The NPS computy WordPress plugin through 2.7.5 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-1746 | MEDIUM | 5.4 | 0.4% | Apr 15, 2024 | The Testimonial Slider WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-1712 | MEDIUM | 4.7 | 0.5% | Apr 15, 2024 | The Carousel Slider WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-1660 | MEDIUM | 4.8 | 0.4% | Apr 15, 2024 | The Top Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-1310 | MEDIUM | 4.9 | 0.7% | Apr 15, 2024 | The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking produ... |
| CVE-2024-1307 | MEDIUM | 6.5 | 0.5% | Apr 15, 2024 | The Smart Forms WordPress plugin before 2.6.94 does not have proper authorization in some actions, which could allow us... |
| CVE-2024-1306 | MEDIUM | 5.4 | 0.2% | Apr 15, 2024 | The Smart Forms WordPress plugin before 2.6.94 does not have CSRF checks in some places, which could allow attackers to... |
| CVE-2024-1204 | MEDIUM | 4.3 | 0.5% | Apr 15, 2024 | The Meta Box WordPress plugin before 5.9.4 does not prevent users with at least the contributor role from access arbitr... |
| CVE-2024-0902 | MEDIUM | 4.8 | 0.4% | Apr 15, 2024 | The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could... |
| CVE-2024-0399 | HIGH | 8.1 | 2.9% | Apr 15, 2024 | The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before ... |
| CVE-2024-3778 | HIGH | 7.2 | 0.6% | Apr 15, 2024 | The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attacker... |
| CVE-2024-3777 | CRITICAL | 9.8 | 0.7% | Apr 15, 2024 | The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset... |
| CVE-2024-3776 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated re... |
| CVE-2024-3775 | HIGH | 7.5 | 0.4% | Apr 15, 2024 | aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user inpu... |
| CVE-2024-3769 | CRITICAL | 9.8 | 0.9% | Apr 15, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an un... |
| CVE-2024-3768 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue... |
| CVE-2024-3767 | HIGH | 8.8 | 0.8% | Apr 15, 2024 | A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code ... |
| CVE-2024-1655 | HIGH | 8.8 | 2.0% | Apr 15, 2024 | Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to... |
| CVE-2024-3774 | MEDIUM | 5.3 | 0.4% | Apr 15, 2024 | aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restriction... |
| CVE-2024-3772 | HIGH | 7.5 | 0.9% | Apr 15, 2024 | Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service vi... |
| CVE-2024-3766 | LOW | 2.4 | 0.4% | Apr 15, 2024 | A vulnerability, which was classified as problematic, has been found in slowlyo OwlAdmin up to 3.5.7. Affected by this i... |
| CVE-2024-29844 | CRITICAL | 9.8 | 0.6% | Apr 15, 2024 | Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to p... |
| CVE-2024-29843 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-29842 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now