2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0609 | MEDIUM | 6.1 | 0.5% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-0608 | MEDIUM | 6.5 | 0.5% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-2936 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in... |
| CVE-2024-2844 | MEDIUM | 4.3 | 0.4% | Mar 29, 2024 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v... |
| CVE-2024-2842 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calend... |
| CVE-2024-28960 | HIGH | 8.2 | 0.8% | Mar 29, 2024 | An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C... |
| CVE-2024-3077 | MEDIUM | 6.5 | 0.5% | Mar 29, 2024 | An malicious BLE device can crash BLE victim device by sending malformed gatt packet |
| CVE-2024-2841 | MEDIUM | 5.4 | 0.3% | Mar 29, 2024 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store... |
| CVE-2024-2475 | MEDIUM | 5.4 | 0.4% | Mar 29, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode... |
| CVE-2024-1729 | MEDIUM | 5.9 | 0.5% | Mar 29, 2024 | A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in rout... |
| CVE-2024-29489 | MEDIUM | 5.5 | 0.3% | Mar 28, 2024 | Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type. |
| CVE-2024-29316 | MEDIUM | 6.3 | 0.4% | Mar 28, 2024 | NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs f... |
| CVE-2024-28714 | HIGH | 8.1 | 0.8% | Mar 28, 2024 | SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the... |
| CVE-2024-28456 | MEDIUM | 5.4 | 0.7% | Mar 28, 2024 | Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to ex... |
| CVE-2024-24407 | MEDIUM | 5.3 | 0.6% | Mar 28, 2024 | SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive informa... |
| CVE-2024-23727 | HIGH | 8.4 | 0.5% | Mar 28, 2024 | The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker ... |
| CVE-2024-28091 | MEDIUM | 6.1 | 0.4% | Mar 28, 2024 | Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proxi... |
| CVE-2024-28090 | MEDIUM | 5.4 | 3.6% | Mar 28, 2024 | Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proxi... |
| CVE-2024-25506 | MEDIUM | 6.5 | 0.3% | Mar 28, 2024 | Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitra... |
| CVE-2024-3019 | HIGH | 8.8 | 1.0% | Mar 28, 2024 | A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowi... |
| CVE-2024-31065 | MEDIUM | 6.1 | 0.8% | Mar 28, 2024 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ... |
| CVE-2024-31064 | MEDIUM | 6.1 | 0.9% | Mar 28, 2024 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ... |
| CVE-2024-31063 | MEDIUM | 6.4 | 0.9% | Mar 28, 2024 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ... |
| CVE-2024-31062 | MEDIUM | 6.3 | 0.8% | Mar 28, 2024 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ... |
| CVE-2024-31061 | MEDIUM | 6.1 | 0.9% | Mar 28, 2024 | Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now