2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1125 | MEDIUM | 5.4 | 0.3% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data d... |
| CVE-2024-1124 | MEDIUM | 4.3 | 0.3% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending ... |
| CVE-2024-1123 | MEDIUM | 6.5 | 0.4% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification o... |
| CVE-2024-25951 | HIGH | 8 | 0.8% | Mar 9, 2024 | A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the under... |
| CVE-2024-28184 | HIGH | 7.4 | 0.6% | Mar 9, 2024 | WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attach... |
| CVE-2024-28180 | MEDIUM | 4.3 | 2.0% | Mar 9, 2024 | Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An atta... |
| CVE-2024-28176 | MEDIUM | 5.9 | 2.1% | Mar 9, 2024 | jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web ... |
| CVE-2024-28122 | MEDIUM | 6.8 | 0.6% | Mar 9, 2024 | JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerabili... |
| CVE-2024-28754 | HIGH | 7.5 | 0.9% | Mar 9, 2024 | RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via ... |
| CVE-2024-28753 | MEDIUM | 6.5 | 0.7% | Mar 9, 2024 | RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request. |
| CVE-2024-2339 | HIGH | 8.8 | 0.6% | Mar 8, 2024 | PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to elevate to superuser. A user... |
| CVE-2024-2338 | HIGH | 7.5 | 0.5% | Mar 8, 2024 | PostgreSQL Anonymizer v1.2 contains a SQL injection vulnerability that allows a user who owns a table to elevate to supe... |
| CVE-2024-21901 | MEDIUM | 4.7 | 18.7% | Mar 8, 2024 | A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authe... |
| CVE-2024-21900 | MEDIUM | 6.5 | 9.4% | Mar 8, 2024 | An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnera... |
| CVE-2024-21899 | CRITICAL | 9.8 | 24.4% | Mar 8, 2024 | An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploite... |
| CVE-2024-2319 | MEDIUM | 6.1 | 0.4% | Mar 8, 2024 | Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could sto... |
| CVE-2024-2318 | HIGH | 7.5 | 0.9% | Mar 8, 2024 | A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affect... |
| CVE-2024-2317 | CRITICAL | 9.1 | 0.8% | Mar 8, 2024 | A vulnerability was found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This issue affect... |
| CVE-2024-2316 | MEDIUM | 4.3 | 0.4% | Mar 8, 2024 | A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnera... |
| CVE-2024-2298 | MEDIUM | 4.3 | 0.3% | Mar 8, 2024 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi... |
| CVE-2024-1851 | MEDIUM | 6.5 | 0.3% | Mar 8, 2024 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi... |
| CVE-2024-27613 | HIGH | 7.3 | 0.5% | Mar 8, 2024 | Numbas editor before 7.3 mishandles reading of themes and extensions. |
| CVE-2024-27612 | MEDIUM | 6.2 | 10.7% | Mar 8, 2024 | Numbas editor before 7.3 mishandles editing of themes and extensions. |
| CVE-2024-1987 | MEDIUM | 5.4 | 0.4% | Mar 8, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor... |
| CVE-2024-2285 | MEDIUM | 6.1 | 0.5% | Mar 8, 2024 | A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. A... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now