2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0609MEDIUM6.1The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-0608MEDIUM6.5The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-2936MEDIUM5.4The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id attribute of widgets in...
CVE-2024-2844MEDIUM4.3The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to insufficient user v...
CVE-2024-2842MEDIUM5.4The Easy Appointments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ea_full_calend...
CVE-2024-28960HIGH8.2An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C...
CVE-2024-3077MEDIUM6.5An malicious BLE device can crash BLE victim device by sending malformed gatt packet
CVE-2024-2841MEDIUM5.4The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Store...
CVE-2024-2475MEDIUM5.4The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode...
CVE-2024-1729MEDIUM5.9A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in rout...
CVE-2024-29489MEDIUM5.5Jerryscript 2.4.0 has SEGV at ./jerry-core/ecma/base/ecma-helpers.c:238:58 in ecma_get_object_type.
CVE-2024-29316MEDIUM6.3NodeBB 3.6.7 is vulnerable to Incorrect Access Control, e.g., a low-privileged attacker can access the restricted tabs f...
CVE-2024-28714HIGH8.1SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the...
CVE-2024-28456MEDIUM5.4Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to ex...
CVE-2024-24407MEDIUM5.3SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive informa...
CVE-2024-23727HIGH8.4The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker ...
CVE-2024-28091MEDIUM6.1Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proxi...
CVE-2024-28090MEDIUM5.4Technicolor TC8715D TC8715D-01.EF.04.38.00-180405-S-FF9-D RSE-TC8717T devices allow a remote attacker within Wi-Fi proxi...
CVE-2024-25506MEDIUM6.5Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitra...
CVE-2024-3019HIGH8.8A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowi...
CVE-2024-31065MEDIUM6.1Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ...
CVE-2024-31064MEDIUM6.1Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ...
CVE-2024-31063MEDIUM6.4Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ...
CVE-2024-31062MEDIUM6.3Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ...
CVE-2024-31061MEDIUM6.1Cross Site Scripting vulnerability in Insurance Mangement System v.1.0.0 and before allows a remote attacker to execute ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now