2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22780 | MEDIUM | 6.1 | 0.7% | Apr 2, 2024 | Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a cra... |
| CVE-2024-30965 | HIGH | 8.8 | 0.4% | Apr 2, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php... |
| CVE-2024-30621 | CRITICAL | 9.8 | 0.7% | Apr 2, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan. |
| CVE-2024-30620 | CRITICAL | 9.8 | 0.8% | Apr 2, 2024 | Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan. |
| CVE-2024-30946 | MEDIUM | 5.5 | 0.2% | Apr 2, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php. |
| CVE-2024-2389 | CRITICAL | 9.8 | 93.9% | Apr 2, 2024 | In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified... |
| CVE-2024-29514 | HIGH | 8.8 | 1.3% | Apr 2, 2024 | File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via upload... |
| CVE-2024-29949 | HIGH | 7.2 | 1.3% | Apr 2, 2024 | There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administr... |
| CVE-2024-29948 | LOW | 3.8 | 0.4% | Apr 2, 2024 | There is an out-of-bounds read vulnerability in some Hikvision NVRs. An authenticated attacker could exploit this vulner... |
| CVE-2024-29947 | LOW | 2.7 | 0.4% | Apr 2, 2024 | There is a NULL dereference pointer vulnerability in some Hikvision NVRs. Due to an insufficient validation of a paramet... |
| CVE-2024-2745 | LOW | 3.3 | 0.2% | Apr 2, 2024 | Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sens... |
| CVE-2024-1946 | MEDIUM | 6.4 | 0.3% | Apr 2, 2024 | The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the block content in all versio... |
| CVE-2024-1807 | MEDIUM | 6.5 | 0.6% | Apr 2, 2024 | The Product Sort and Display for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due... |
| CVE-2024-1732 | MEDIUM | 5.3 | 0.4% | Apr 2, 2024 | The Sharkdropship for AliExpress Dropshipping and Affiliate plugin for WordPress is vulnerable to unauthorized loss of d... |
| CVE-2024-2931 | MEDIUM | 4.3 | 0.5% | Apr 2, 2024 | The WPFront User Role Editor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
| CVE-2024-31005 | HIGH | 8.1 | 1.2% | Apr 2, 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_Mdhd... |
| CVE-2024-31004 | CRITICAL | 9.8 | 1.5% | Apr 2, 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_Stsd... |
| CVE-2024-31003 | HIGH | 8.8 | 1.5% | Apr 2, 2024 | Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4... |
| CVE-2024-31002 | CRITICAL | 9.8 | 1.4% | Apr 2, 2024 | Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4... |
| CVE-2024-20799 | MEDIUM | 5.4 | 0.4% | Apr 2, 2024 | Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2024-1300 | MEDIUM | 5.4 | 1.1% | Apr 2, 2024 | A vulnerability in the Eclipse Vert.x toolkit causes a memory leak in TCP servers configured with TLS and SNI support. W... |
| CVE-2024-2925 | MEDIUM | 5.4 | 0.4% | Apr 2, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-2839 | MEDIUM | 5.4 | 0.3% | Apr 2, 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'colibri_pos... |
| CVE-2024-29276 | CRITICAL | 9.8 | 32.8% | Apr 2, 2024 | An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess m... |
| CVE-2024-29086 | MEDIUM | 5.5 | 0.2% | Apr 2, 2024 | in OpenHarmony v3.2.4 and prior versions allow a local attacker cause DOS through stack overflow. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now