2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27094 | HIGH | 7.4 | 0.8% | Mar 21, 2024 | OpenZeppelin Contracts is a library for secure smart contract development. The `Base64.encode` function encodes a `bytes... |
| CVE-2024-26196 | MEDIUM | 4.3 | 1.2% | Mar 21, 2024 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-25811 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information. |
| CVE-2024-25359 | MEDIUM | 6.6 | 0.3% | Mar 21, 2024 | An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of ... |
| CVE-2024-25239 | CRITICAL | 9.8 | 0.8% | Mar 21, 2024 | SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL comm... |
| CVE-2024-25167 | MEDIUM | 6.1 | 0.6% | Mar 21, 2024 | Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script... |
| CVE-2024-24818 | MEDIUM | 5.9 | 0.6% | Mar 21, 2024 | EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "P... |
| CVE-2024-24813 | HIGH | 7.5 | 0.6% | Mar 21, 2024 | Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular ... |
| CVE-2024-24520 | HIGH | 7.8 | 0.4% | Mar 21, 2024 | An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languag... |
| CVE-2024-24110 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET r... |
| CVE-2024-24028 | MEDIUM | 5.9 | 0.2% | Mar 21, 2024 | Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information... |
| CVE-2024-22352 | MEDIUM | 5.5 | 0.5% | Mar 21, 2024 | IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a loc... |
| CVE-2024-1908 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us... |
| CVE-2024-1503 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-1502 | MEDIUM | 4.3 | 0.4% | Mar 21, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due... |
| CVE-2024-1450 | MEDIUM | 5.4 | 0.5% | Mar 21, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco... |
| CVE-2024-1326 | MEDIUM | 5.4 | 0.5% | Mar 21, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all v... |
| CVE-2024-1278 | MEDIUM | 5.4 | 0.4% | Mar 21, 2024 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-1214 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req... |
| CVE-2024-1213 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req... |
| CVE-2024-1202 | CRITICAL | 9.8 | 0.9% | Mar 21, 2024 | Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass. This issue affe... |
| CVE-2024-1142 | MEDIUM | 5.4 | 0.7% | Mar 21, 2024 | Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files... |
| CVE-2024-0966 | MEDIUM | 5.4 | 0.5% | Mar 21, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco... |
| CVE-2024-2748 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execut... |
| CVE-2024-28916 | HIGH | 8.8 | 0.7% | Mar 21, 2024 | Xbox Gaming Services Elevation of Privilege Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now