2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30511 | MEDIUM | 5.3 | 0.5% | Mar 29, 2024 | Insertion of Sensitive Information into Log File vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce.This issu... |
| CVE-2024-30492 | MEDIUM | 4.3 | 0.5% | Mar 29, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebToffee Import Export ... |
| CVE-2024-30482 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Re... |
| CVE-2024-30477 | CRITICAL | 9.8 | 0.5% | Mar 29, 2024 | Missing Authorization vulnerability in Klarna Klarna Payments for WooCommerce.This issue affects Klarna Payments for Woo... |
| CVE-2024-30469 | MEDIUM | 5.3 | 0.4% | Mar 29, 2024 | Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce:... |
| CVE-2024-30247 | CRITICAL | 9.8 | 2.1% | Mar 29, 2024 | NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command i... |
| CVE-2024-30246 | HIGH | 7.1 | 0.6% | Mar 29, 2024 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could ... |
| CVE-2024-29904 | HIGH | 7.5 | 0.8% | Mar 29, 2024 | CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. ... |
| CVE-2024-29901 | HIGH | 8.1 | 0.7% | Mar 29, 2024 | The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with N... |
| CVE-2024-29900 | HIGH | 7.5 | 0.6% | Mar 29, 2024 | Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files... |
| CVE-2024-29686 | HIGH | 7.2 | 1.8% | Mar 29, 2024 | Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary ... |
| CVE-2024-3081 | MEDIUM | 5.4 | 0.5% | Mar 29, 2024 | A vulnerability was found in EasyCorp EasyAdmin up to 4.8.9. It has been declared as problematic. Affected by this vulne... |
| CVE-2024-30508 | CRITICAL | 9.8 | 0.5% | Mar 29, 2024 | Missing Authorization vulnerability in ThimPress WP Hotel Booking.This issue affects WP Hotel Booking: from n/a through ... |
| CVE-2024-30507 | LOW | 2.7 | 0.4% | Mar 29, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Molongui.This issue affects Molongui: from n/a through... |
| CVE-2024-30506 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vsourz Digital All... |
| CVE-2024-30505 | MEDIUM | 6.5 | 0.5% | Mar 29, 2024 | Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th... |
| CVE-2024-30504 | HIGH | 7.2 | 0.6% | Mar 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.T... |
| CVE-2024-30502 | CRITICAL | 9.8 | 2.3% | Mar 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel Engine.T... |
| CVE-2024-29893 | MEDIUM | 6.5 | 1.0% | Mar 29, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of ArgoCD starting from v2.4 have... |
| CVE-2024-29890 | HIGH | 8.8 | 0.8% | Mar 29, 2024 | DataLens is a business intelligence and data visualization system. A specifically crafted request allowed the creation o... |
| CVE-2024-29202 | CRITICAL | 9.9 | 5.9% | Mar 29, 2024 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit ... |
| CVE-2024-29201 | CRITICAL | 9.9 | 5.9% | Mar 29, 2024 | JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass t... |
| CVE-2024-29024 | MEDIUM | 5.3 | 0.2% | Mar 29, 2024 | JumpServer is an open source bastion host and an operation and maintenance security audit system. An authenticated user ... |
| CVE-2024-29020 | MEDIUM | 5.3 | 0.3% | Mar 29, 2024 | JumpServer is an open source bastion host and an operation and maintenance security audit system. An authorized attacker... |
| CVE-2024-28867 | HIGH | 7.4 | 0.6% | Mar 29, 2024 | Swift Prometheus is a Swift client for the Prometheus monitoring system, supporting counters, gauges and histograms. In ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now