2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24868 | HIGH | 8.8 | 0.5% | Feb 28, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro... |
| CVE-2024-21886 | HIGH | 7.8 | 1.4% | Feb 28, 2024 | A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an appli... |
| CVE-2024-21885 | HIGH | 7.8 | 1.4% | Feb 28, 2024 | A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated arr... |
| CVE-2024-1965 | MEDIUM | 5.3 | 0.4% | Feb 28, 2024 | Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could ... |
| CVE-2024-1808 | MEDIUM | 5.4 | 0.3% | Feb 28, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-26016 | MEDIUM | 5.4 | 0.9% | Feb 28, 2024 | A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then ... |
| CVE-2024-24779 | MEDIUM | 6.5 | 0.7% | Feb 28, 2024 | Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows fo... |
| CVE-2024-24773 | MEDIUM | 6.5 | 0.8% | Feb 28, 2024 | Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization ... |
| CVE-2024-24772 | MEDIUM | 4.3 | 0.9% | Feb 28, 2024 | A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information ... |
| CVE-2024-1636 | MEDIUM | 5.4 | 0.4% | Feb 28, 2024 | Potential Cross-Site Scripting (XSS) in the page editing area. |
| CVE-2024-1632 | MEDIUM | 6.5 | 0.5% | Feb 28, 2024 | Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrati... |
| CVE-2024-27315 | MEDIUM | 4.3 | 1.0% | Feb 28, 2024 | An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially cr... |
| CVE-2024-1861 | MEDIUM | 4.3 | 0.4% | Feb 28, 2024 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v... |
| CVE-2024-1860 | MEDIUM | 5.3 | 0.4% | Feb 28, 2024 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v... |
| CVE-2024-1719 | MEDIUM | 4.3 | 0.3% | Feb 28, 2024 | The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2024-22459 | MEDIUM | 6.5 | 0.5% | Feb 28, 2024 | Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper a... |
| CVE-2024-1954 | MEDIUM | 6.3 | 0.2% | Feb 28, 2024 | The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in a... |
| CVE-2024-1791 | MEDIUM | 5.4 | 0.4% | Feb 28, 2024 | The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all... |
| CVE-2024-1566 | MEDIUM | 6.5 | 0.5% | Feb 28, 2024 | The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2024-1516 | MEDIUM | 5.3 | 0.4% | Feb 28, 2024 | The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability ... |
| CVE-2024-1514 | HIGH | 7.5 | 0.7% | Feb 28, 2024 | The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter ... |
| CVE-2024-1476 | MEDIUM | 5.3 | 0.5% | Feb 28, 2024 | The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu... |
| CVE-2024-1368 | MEDIUM | 5.3 | 0.4% | Feb 28, 2024 | The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2024-1136 | MEDIUM | 5.3 | 0.5% | Feb 28, 2024 | The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an impr... |
| CVE-2024-0975 | MEDIUM | 5.3 | 0.5% | Feb 28, 2024 | The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now