2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28119 | HIGH | 8.8 | 1.6% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ... |
| CVE-2024-28118 | HIGH | 8.8 | 1.2% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to ... |
| CVE-2024-28117 | HIGH | 8.8 | 1.4% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible function... |
| CVE-2024-28116 | HIGH | 8.8 | 5.8% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-... |
| CVE-2024-28029 | HIGH | 8.8 | 0.7% | Mar 21, 2024 | Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authoriza... |
| CVE-2024-27921 | HIGH | 8.8 | 60.6% | Mar 21, 2024 | Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identif... |
| CVE-2024-25937 | HIGH | 8.8 | 8.5% | Mar 21, 2024 | SQL injection vulnerability exists in the script DIAE_tagHandler.ashx. |
| CVE-2024-24272 | HIGH | 7.1 | 0.2% | Mar 21, 2024 | An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive inf... |
| CVE-2024-2767 | MEDIUM | 6.5 | 0.5% | Mar 21, 2024 | A vulnerability was found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critical. T... |
| CVE-2024-2766 | MEDIUM | 6.5 | 0.5% | Mar 21, 2024 | A vulnerability has been found in Campcodes Complete Online Beauty Parlor Management System 1.0 and classified as critic... |
| CVE-2024-2764 | HIGH | 8.8 | 1.5% | Mar 21, 2024 | A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formS... |
| CVE-2024-2763 | HIGH | 8.8 | 1.5% | Mar 21, 2024 | A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is ... |
| CVE-2024-28756 | MEDIUM | 5.9 | 0.2% | Mar 21, 2024 | The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machi... |
| CVE-2024-1727 | MEDIUM | 4.3 | 0.4% | Mar 21, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files t... |
| CVE-2024-29374 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | A Cross-Site Scripting (XSS) vulnerability exists in the way MOODLE 3.10.9 handles user input within the "GET /?lang=" U... |
| CVE-2024-2580 | MEDIUM | 6.5 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelKit Automati... |
| CVE-2024-2579 | MEDIUM | 5.9 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking C... |
| CVE-2024-2578 | MEDIUM | 4.8 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPCoder WP Coder a... |
| CVE-2024-29916 | MEDIUM | 5.6 | 0.3% | Mar 21, 2024 | The dormakaba Saflok system before the November 2023 software update allows an attacker to unlock arbitrary doors at a p... |
| CVE-2024-29180 | HIGH | 7.5 | 1.2% | Mar 21, 2024 | Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not valida... |
| CVE-2024-27968 | MEDIUM | 6.1 | 0.2% | Mar 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue... |
| CVE-2024-27965 | MEDIUM | 4.8 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnel... |
| CVE-2024-27964 | HIGH | 8.8 | 0.6% | Mar 21, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: ... |
| CVE-2024-27963 | MEDIUM | 5.4 | 0.3% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Store... |
| CVE-2024-27962 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now