2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31372 | MEDIUM | 4.3 | 0.2% | Apr 12, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Arnan de Gans No-Bot Registration.This issue affects No-Bot Registrat... |
| CVE-2024-31371 | MEDIUM | 4.3 | 0.2% | Apr 12, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Xylus Themes WP Event Aggregator.This issue affects WP Event Aggregat... |
| CVE-2024-3400 | CRITICAL | 10 | 100.0% | Apr 12, 2024 | A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo... |
| CVE-2024-29400 | HIGH | 7.5 | 0.6% | Apr 12, 2024 | An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter. |
| CVE-2024-27309 | HIGH | 7.4 | 1.1% | Apr 12, 2024 | While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correc... |
| CVE-2024-22526 | MEDIUM | 5.5 | 0.4% | Apr 12, 2024 | Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via... |
| CVE-2024-30850 | — | — | — | Apr 12, 2024 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-... |
| CVE-2024-30614 | MEDIUM | 5.3 | 0.5% | Apr 12, 2024 | An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the e... |
| CVE-2024-22734 | MEDIUM | 6.2 | 0.7% | Apr 12, 2024 | An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attack... |
| CVE-2024-2801 | MEDIUM | 6.4 | 0.4% | Apr 12, 2024 | The Shopkeeper Extender plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_slide'... |
| CVE-2024-2137 | MEDIUM | 5.4 | 0.3% | Apr 12, 2024 | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via mu... |
| CVE-2024-22357 | MEDIUM | 5.4 | 0.4% | Apr 12, 2024 | IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site sc... |
| CVE-2024-3092 | MEDIUM | 5.4 | 0.5% | Apr 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions start... |
| CVE-2024-2279 | MEDIUM | 5.4 | 0.6% | Apr 12, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting f... |
| CVE-2024-28458 | HIGH | 7.5 | 0.7% | Apr 11, 2024 | Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the fun... |
| CVE-2024-27592 | MEDIUM | 4.3 | 0.5% | Apr 11, 2024 | Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via app... |
| CVE-2024-25852 | HIGH | 8.8 | 16.5% | Apr 11, 2024 | Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter ... |
| CVE-2024-25376 | HIGH | 7.8 | 0.4% | Apr 11, 2024 | An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a l... |
| CVE-2024-29454 | — | — | — | Apr 11, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-22722 | HIGH | 7.2 | 0.9% | Apr 11, 2024 | Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via t... |
| CVE-2024-22721 | MEDIUM | 6.3 | 0.2% | Apr 11, 2024 | Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data v... |
| CVE-2024-22719 | HIGH | 8.1 | 0.5% | Apr 11, 2024 | SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when se... |
| CVE-2024-22718 | CRITICAL | 9.6 | 0.7% | Apr 11, 2024 | Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id pa... |
| CVE-2024-22717 | MEDIUM | 6.1 | 0.4% | Apr 11, 2024 | Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name f... |
| CVE-2024-30273 | HIGH | 7.8 | 0.4% | Apr 11, 2024 | Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could res... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now