2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1582 | MEDIUM | 5.4 | 0.3% | Mar 13, 2024 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-1421 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘b... |
| CVE-2024-1397 | MEDIUM | 5.4 | 0.5% | Mar 12, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-2395 | MEDIUM | 4.3 | 0.2% | Mar 12, 2024 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2024-2107 | HIGH | 7.5 | 0.5% | Mar 12, 2024 | The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2024-24101 | CRITICAL | 9.8 | 0.3% | Mar 12, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update. |
| CVE-2024-0386 | MEDIUM | 6.1 | 0.6% | Mar 12, 2024 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versi... |
| CVE-2024-2406 | CRITICAL | 9.8 | 0.6% | Mar 12, 2024 | A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index... |
| CVE-2024-28239 | MEDIUM | 4.3 | 0.6% | Mar 12, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect`... |
| CVE-2024-28238 | LOW | 2.3 | 0.2% | Mar 12, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is... |
| CVE-2024-28236 | MEDIUM | 6.5 | 0.7% | Mar 12, 2024 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines ca... |
| CVE-2024-27305 | MEDIUM | 5.3 | 0.4% | Mar 12, 2024 | aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP sm... |
| CVE-2024-24097 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary... |
| CVE-2024-24093 | CRITICAL | 9.8 | 0.6% | Mar 12, 2024 | SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Per... |
| CVE-2024-24092 | HIGH | 7.8 | 0.3% | Mar 12, 2024 | SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via... |
| CVE-2024-23300 | HIGH | 7.8 | 0.3% | Mar 12, 2024 | A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Process... |
| CVE-2024-2130 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versio... |
| CVE-2024-2031 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoo... |
| CVE-2024-28186 | HIGH | 7.1 | 0.6% | Mar 12, 2024 | FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free ... |
| CVE-2024-28121 | HIGH | 8.8 | 1.6% | Mar 12, 2024 | stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and ... |
| CVE-2024-28114 | CRITICAL | 9.1 | 1.3% | Mar 12, 2024 | Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to ... |
| CVE-2024-28113 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arb... |
| CVE-2024-28112 | MEDIUM | 4.8 | 0.3% | Mar 12, 2024 | Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored... |
| CVE-2024-28098 | MEDIUM | 5.4 | 1.7% | Mar 12, 2024 | The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, su... |
| CVE-2024-27894 | HIGH | 8.8 | 1.9% | Mar 12, 2024 | The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now