2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26574 | HIGH | 7.8 | 0.3% | Apr 8, 2024 | Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code vi... |
| CVE-2024-3438 | CRITICAL | 9.8 | 0.9% | Apr 8, 2024 | A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects ... |
| CVE-2024-27897 | HIGH | 7.5 | 0.3% | Apr 8, 2024 | Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect se... |
| CVE-2024-27896 | HIGH | 7.5 | 0.3% | Apr 8, 2024 | Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect int... |
| CVE-2024-27895 | HIGH | 7.5 | 0.3% | Apr 8, 2024 | Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confi... |
| CVE-2024-26811 | MEDIUM | 5.5 | 0.3% | Apr 8, 2024 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If in... |
| CVE-2024-31375 | MEDIUM | 5.4 | 0.4% | Apr 8, 2024 | Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a ... |
| CVE-2024-31357 | MEDIUM | 6.5 | 0.4% | Apr 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate ... |
| CVE-2024-23192 | MEDIUM | 6.1 | 0.5% | Apr 8, 2024 | RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when ... |
| CVE-2024-23191 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | Upsell advertisement information of an account can be manipulated to execute script code in the context of the users bro... |
| CVE-2024-23190 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | Upsell shop information of an account can be manipulated to execute script code in the context of the users browser sess... |
| CVE-2024-23189 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | Embedded content references at tasks could be used to temporarily execute script code in the context of the users browse... |
| CVE-2024-30675 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30674 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30672 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30667 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30666 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30665 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30663 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30662 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30661 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30659 | — | — | — | Apr 8, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31022 | CRITICAL | 9.8 | 0.9% | Apr 8, 2024 | An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php... |
| CVE-2024-27488 | CRITICAL | 9.8 | 0.6% | Apr 8, 2024 | Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privi... |
| CVE-2024-1958 | MEDIUM | 4.8 | 0.5% | Apr 8, 2024 | The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now