2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1500 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo ... |
| CVE-2024-1377 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_ta... |
| CVE-2024-1366 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_... |
| CVE-2024-28216 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which ... |
| CVE-2024-28215 | HIGH | 7.5 | 0.5% | Mar 7, 2024 | nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which ... |
| CVE-2024-28214 | LOW | 2.7 | 0.6% | Mar 7, 2024 | nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote at... |
| CVE-2024-28213 | CRITICAL | 9.8 | 1.2% | Mar 7, 2024 | nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote atta... |
| CVE-2024-28212 | CRITICAL | 9.8 | 1.0% | Mar 7, 2024 | nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via uns... |
| CVE-2024-28211 | CRITICAL | 9.8 | 0.8% | Mar 7, 2024 | nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing ar... |
| CVE-2024-1761 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all v... |
| CVE-2024-28097 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting all... |
| CVE-2024-28096 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowi... |
| CVE-2024-28095 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing... |
| CVE-2024-28094 | HIGH | 8.8 | 0.6% | Mar 7, 2024 | Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the au... |
| CVE-2024-0815 | HIGH | 8.8 | 1.1% | Mar 7, 2024 | Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0 |
| CVE-2024-1460 | MEDIUM | 4.4 | 0.2% | Mar 7, 2024 | MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code... |
| CVE-2024-1443 | MEDIUM | 4.4 | 0.2% | Mar 7, 2024 | MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code ... |
| CVE-2024-24389 | MEDIUM | 6.1 | 0.3% | Mar 7, 2024 | A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts o... |
| CVE-2024-0817 | HIGH | 7.8 | 1.2% | Mar 7, 2024 | Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0 |
| CVE-2024-26566 | HIGH | 8.2 | 0.6% | Mar 7, 2024 | An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification co... |
| CVE-2024-24375 | HIGH | 7.5 | 0.5% | Mar 7, 2024 | SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/adm... |
| CVE-2024-22857 | CRITICAL | 9.8 | 1.7% | Mar 7, 2024 | Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but... |
| CVE-2024-1299 | HIGH | 8.1 | 0.5% | Mar 7, 2024 | A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to ... |
| CVE-2024-0199 | HIGH | 8 | 0.7% | Mar 7, 2024 | An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to ... |
| CVE-2024-2236 | MEDIUM | 5.9 | 1.1% | Mar 6, 2024 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now