2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1725 | MEDIUM | 6.5 | 0.6% | Mar 7, 2024 | A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue coul... |
| CVE-2024-0203 | HIGH | 8.8 | 0.3% | Mar 7, 2024 | The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. Thi... |
| CVE-2024-1773 | HIGH | 8.8 | 1.0% | Mar 7, 2024 | The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all ver... |
| CVE-2024-22752 | HIGH | 8.1 | 0.6% | Mar 7, 2024 | Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use o... |
| CVE-2024-1442 | HIGH | 8.8 | 0.8% | Mar 7, 2024 | A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doin... |
| CVE-2024-27733 | HIGH | 7.7 | 0.3% | Mar 7, 2024 | File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitr... |
| CVE-2024-1351 | CRITICAL | 9.8 | 0.5% | Mar 7, 2024 | Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which ma... |
| CVE-2024-2245 | MEDIUM | 6.1 | 0.3% | Mar 7, 2024 | Cross-Site Scripting vulnerability in moziloCMS version 2.0. By sending a POST request to the '/install.php' endpoint, a... |
| CVE-2024-2241 | MEDIUM | 6.3 | 0.4% | Mar 7, 2024 | Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user... |
| CVE-2024-0818 | CRITICAL | 9.1 | 1.0% | Mar 7, 2024 | Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6 |
| CVE-2024-28230 | MEDIUM | 6.5 | 0.5% | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 attaching/detaching workflow to a project was possible without project admin p... |
| CVE-2024-28229 | MEDIUM | 6.5 | 0.5% | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore issues and articles |
| CVE-2024-28228 | MEDIUM | 5.3 | 0.5% | Mar 7, 2024 | In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in HelpDesk was possible |
| CVE-2024-1170 | HIGH | 8.2 | 0.7% | Mar 7, 2024 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-1169 | HIGH | 7.5 | 0.6% | Mar 7, 2024 | The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p... |
| CVE-2024-22256 | MEDIUM | 4.3 | 0.4% | Mar 7, 2024 | VMware Cloud Director contains a partial information disclosure vulnerability. A malicious actor can potentially gather ... |
| CVE-2024-1931 | HIGH | 7.5 | 2.5% | Mar 7, 2024 | NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of se... |
| CVE-2024-1534 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode... |
| CVE-2024-2136 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Hea... |
| CVE-2024-1382 | HIGH | 8.8 | 0.9% | Mar 7, 2024 | The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ... |
| CVE-2024-0917 | CRITICAL | 9.8 | 1.6% | Mar 7, 2024 | remote code execution in paddlepaddle/paddle 2.6.0 |
| CVE-2024-28222 | CRITICAL | 9.8 | 1.0% | Mar 7, 2024 | In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file... |
| CVE-2024-1506 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title... |
| CVE-2024-1419 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attrib... |
| CVE-2024-1720 | MEDIUM | 6.1 | 0.5% | Mar 7, 2024 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now