2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1956 | MEDIUM | 6.1 | 0.5% | Apr 8, 2024 | The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in t... |
| CVE-2024-1752 | MEDIUM | 6.1 | 0.4% | Apr 8, 2024 | The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-1589 | MEDIUM | 6.1 | 0.4% | Apr 8, 2024 | The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which co... |
| CVE-2024-1588 | MEDIUM | 6.8 | 0.7% | Apr 8, 2024 | The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which co... |
| CVE-2024-1292 | MEDIUM | 4.7 | 0.5% | Apr 8, 2024 | The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back i... |
| CVE-2024-23658 | MEDIUM | 4.4 | 0.1% | Apr 8, 2024 | In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service wi... |
| CVE-2024-28744 | HIGH | 8.8 | 0.3% | Apr 8, 2024 | The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmw... |
| CVE-2024-3437 | HIGH | 7.2 | 1.1% | Apr 8, 2024 | A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe... |
| CVE-2024-3436 | HIGH | 7.2 | 0.9% | Apr 8, 2024 | A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnera... |
| CVE-2024-3434 | MEDIUM | 5.4 | 0.5% | Apr 8, 2024 | A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability ... |
| CVE-2024-3433 | MEDIUM | 5.4 | 0.5% | Apr 7, 2024 | A vulnerability classified as problematic has been found in PuneethReddyHC Event Management 1.0. Affected is an unknown ... |
| CVE-2024-3432 | HIGH | 8.8 | 0.6% | Apr 7, 2024 | A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some... |
| CVE-2024-3431 | HIGH | 8.8 | 0.7% | Apr 7, 2024 | A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of... |
| CVE-2024-3430 | LOW | 2.4 | 0.2% | Apr 7, 2024 | A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an unknow... |
| CVE-2024-31951 | MEDIUM | 6.5 | 0.5% | Apr 7, 2024 | In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash i... |
| CVE-2024-31950 | MEDIUM | 6.5 | 0.5% | Apr 7, 2024 | In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets... |
| CVE-2024-31949 | MEDIUM | 6.5 | 0.7% | Apr 7, 2024 | In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability bec... |
| CVE-2024-31948 | MEDIUM | 6.5 | 0.8% | Apr 7, 2024 | In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the ... |
| CVE-2024-3428 | MEDIUM | 6.1 | 0.6% | Apr 7, 2024 | A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as problematic. This vulnerability... |
| CVE-2024-31349 | MEDIUM | 5.4 | 0.3% | Apr 7, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailMunc... |
| CVE-2024-31348 | MEDIUM | 6.5 | 0.4% | Apr 7, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testim... |
| CVE-2024-31346 | MEDIUM | 6.5 | 0.3% | Apr 7, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksmarket Gradi... |
| CVE-2024-31345 | CRITICAL | 9.1 | 0.9% | Apr 7, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Pos... |
| CVE-2024-31344 | MEDIUM | 5.9 | 0.3% | Apr 7, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative S... |
| CVE-2024-31308 | HIGH | 7.2 | 0.4% | Apr 7, 2024 | Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now