2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31025 | HIGH | 7.5 | 0.6% | Apr 4, 2024 | SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php co... |
| CVE-2024-2919 | MEDIUM | 5.4 | 0.3% | Apr 4, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-2830 | MEDIUM | 6.4 | 0.4% | Apr 4, 2024 | The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-2008 | HIGH | 8.8 | 0.9% | Apr 4, 2024 | The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Inje... |
| CVE-2024-3274 | MEDIUM | 5.3 | 33.5% | Apr 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403... |
| CVE-2024-3030 | MEDIUM | 4.4 | 0.4% | Apr 4, 2024 | The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ... |
| CVE-2024-3022 | HIGH | 7.2 | 1.6% | Apr 4, 2024 | The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in... |
| CVE-2024-2868 | MEDIUM | 6.4 | 0.5% | Apr 4, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-2803 | MEDIUM | 5.4 | 0.3% | Apr 4, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wid... |
| CVE-2024-2692 | CRITICAL | 9 | 0.7% | Apr 4, 2024 | SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vuln... |
| CVE-2024-3273 | CRITICAL | 9.8 | 100.0% | Apr 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325... |
| CVE-2024-3272 | CRITICAL | 9.8 | 98.0% | Apr 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320... |
| CVE-2024-29225 | MEDIUM | 4.3 | 0.3% | Apr 4, 2024 | ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containin... |
| CVE-2024-29167 | HIGH | 7.2 | 0.7% | Apr 4, 2024 | SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execu... |
| CVE-2024-26258 | HIGH | 7.1 | 0.7% | Apr 4, 2024 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to... |
| CVE-2024-25568 | HIGH | 8.8 | 1.1% | Apr 4, 2024 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to ... |
| CVE-2024-3270 | MEDIUM | 6.5 | 0.6% | Apr 3, 2024 | A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code ... |
| CVE-2024-30265 | HIGH | 7.5 | 0.7% | Apr 3, 2024 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboa... |
| CVE-2024-2689 | MEDIUM | 4.4 | 0.5% | Apr 3, 2024 | Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has pe... |
| CVE-2024-29413 | MEDIUM | 5.4 | 0.4% | Apr 3, 2024 | Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant me... |
| CVE-2024-28870 | HIGH | 7.5 | 0.6% | Apr 3, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine dev... |
| CVE-2024-27705 | HIGH | 7.6 | 0.6% | Apr 3, 2024 | Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted P... |
| CVE-2024-27706 | MEDIUM | 6.1 | 0.4% | Apr 3, 2024 | Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of c... |
| CVE-2024-3181 | MEDIUM | 4.8 | 0.4% | Apr 3, 2024 | Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search F... |
| CVE-2024-3180 | MEDIUM | 4.8 | 0.4% | Apr 3, 2024 | Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now