2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1564 | MEDIUM | 4.3 | 0.5% | Mar 25, 2024 | The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access cus... |
| CVE-2024-1232 | MEDIUM | 4.8 | 0.2% | Mar 25, 2024 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac... |
| CVE-2024-1231 | MEDIUM | 6.8 | 0.2% | Mar 25, 2024 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac... |
| CVE-2024-29071 | HIGH | 8.8 | 0.4% | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at... |
| CVE-2024-28041 | HIGH | 8.8 | 0.6% | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary comm... |
| CVE-2024-29188 | HIGH | 7.9 | 0.2% | Mar 24, 2024 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action ... |
| CVE-2024-29187 | HIGH | 7.3 | 0.5% | Mar 24, 2024 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs... |
| CVE-2024-29034 | MEDIUM | 6.1 | 0.4% | Mar 24, 2024 | CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-... |
| CVE-2024-29194 | HIGH | 8.3 | 0.7% | Mar 24, 2024 | OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation o... |
| CVE-2024-2856 | CRITICAL | 9.8 | 1.2% | Mar 24, 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by thi... |
| CVE-2024-2855 | CRITICAL | 9.8 | 1.3% | Mar 24, 2024 | A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. Affected by this vulner... |
| CVE-2024-2854 | CRITICAL | 9.8 | 3.9% | Mar 24, 2024 | A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaCo... |
| CVE-2024-2853 | CRITICAL | 9.8 | 4.0% | Mar 24, 2024 | A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the ... |
| CVE-2024-2852 | CRITICAL | 9.8 | 1.3% | Mar 24, 2024 | A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the... |
| CVE-2024-2851 | CRITICAL | 9.8 | 4.0% | Mar 24, 2024 | A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the... |
| CVE-2024-2850 | CRITICAL | 9.8 | 1.3% | Mar 24, 2024 | A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function s... |
| CVE-2024-30161 | MEDIUM | 6.5 | 0.5% | Mar 24, 2024 | In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly ... |
| CVE-2024-30156 | HIGH | 7.5 | 3.7% | Mar 24, 2024 | Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, all... |
| CVE-2024-24725 | HIGH | 8.8 | 51.3% | Mar 23, 2024 | Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS... |
| CVE-2024-23755 | HIGH | 8.8 | 1.1% | Mar 23, 2024 | ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is in... |
| CVE-2024-1603 | HIGH | 7.5 | 0.6% | Mar 23, 2024 | paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. |
| CVE-2024-2849 | CRITICAL | 9.8 | 0.9% | Mar 23, 2024 | A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. This vulnerability affects u... |
| CVE-2024-24840 | MEDIUM | 5.4 | 0.3% | Mar 23, 2024 | Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor ... |
| CVE-2024-24835 | MEDIUM | 6.5 | 0.4% | Mar 23, 2024 | Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4. |
| CVE-2024-24832 | HIGH | 7.5 | 0.4% | Mar 23, 2024 | Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now