2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0611 | MEDIUM | 4.8 | 0.7% | Mar 2, 2024 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sl... |
| CVE-2024-0378 | MEDIUM | 6.1 | 0.6% | Mar 2, 2024 | The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-1775 | MEDIUM | 5.4 | 0.4% | Mar 2, 2024 | The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting ... |
| CVE-2024-1592 | MEDIUM | 4.3 | 0.2% | Mar 2, 2024 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-25064 | MEDIUM | 4.3 | 0.4% | Mar 2, 2024 | Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the at... |
| CVE-2024-25063 | HIGH | 7.5 | 0.6% | Mar 2, 2024 | Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain a... |
| CVE-2024-27355 | HIGH | 7.5 | 0.6% | Mar 1, 2024 | An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the AS... |
| CVE-2024-27354 | HIGH | 7.5 | 0.6% | Mar 1, 2024 | An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can constr... |
| CVE-2024-25438 | MEDIUM | 6.1 | 0.4% | Mar 1, 2024 | A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrar... |
| CVE-2024-25436 | MEDIUM | 6.1 | 0.4% | Mar 1, 2024 | A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrar... |
| CVE-2024-25434 | MEDIUM | 5.4 | 0.4% | Mar 1, 2024 | A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via... |
| CVE-2024-24512 | MEDIUM | 6.1 | 0.5% | Mar 1, 2024 | Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle ... |
| CVE-2024-24511 | MEDIUM | 6.1 | 0.5% | Mar 1, 2024 | Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title com... |
| CVE-2024-27747 | CRITICAL | 9.8 | 23.6% | Mar 1, 2024 | File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a cra... |
| CVE-2024-27746 | CRITICAL | 9.8 | 12.9% | Mar 1, 2024 | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a c... |
| CVE-2024-27744 | MEDIUM | 6.1 | 1.3% | Mar 1, 2024 | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code ... |
| CVE-2024-27743 | MEDIUM | 6.1 | 1.3% | Mar 1, 2024 | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code ... |
| CVE-2024-1869 | HIGH | 7.5 | 2.3% | Mar 1, 2024 | Certain HP DesignJet print products are potentially vulnerable to information disclosure related to accessing memory out... |
| CVE-2024-27101 | CRITICAL | 9.1 | 0.5% | Mar 1, 2024 | SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application per... |
| CVE-2024-23492 | MEDIUM | 5.7 | 0.2% | Mar 1, 2024 | A weak encoding is used to transmit credentials for WS203VICM. |
| CVE-2024-22182 | HIGH | 8.6 | 0.6% | Mar 1, 2024 | A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM caus... |
| CVE-2024-21767 | CRITICAL | 9.4 | 0.6% | Mar 1, 2024 | A remote attacker may be able to bypass access control of Commend WS203VICM by creating a malicious request. |
| CVE-2024-20328 | MEDIUM | 5.3 | 84.8% | Mar 1, 2024 | A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the p... |
| CVE-2024-1174 | HIGH | 8.2 | 0.2% | Mar 1, 2024 | Previous versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP ha... |
| CVE-2024-2077 | CRITICAL | 9.8 | 0.7% | Mar 1, 2024 | A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now