2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1698 | CRITICAL | 9.8 | 77.6% | Feb 27, 2024 | The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for... |
| CVE-2024-1687 | MEDIUM | 5.4 | 0.4% | Feb 27, 2024 | The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized e... |
| CVE-2024-1686 | MEDIUM | 4.3 | 0.4% | Feb 27, 2024 | The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing author... |
| CVE-2024-0759 | HIGH | 7.5 | 1.0% | Feb 27, 2024 | Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission l... |
| CVE-2024-1323 | MEDIUM | 5.4 | 0.5% | Feb 27, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type ... |
| CVE-2024-25711 | HIGH | 7.5 | 1.0% | Feb 27, 2024 | diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as .... |
| CVE-2024-24100 | HIGH | 8.3 | 0.6% | Feb 27, 2024 | Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID. |
| CVE-2024-24099 | MEDIUM | 5.4 | 0.4% | Feb 27, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update. |
| CVE-2024-24096 | HIGH | 7.8 | 0.4% | Feb 27, 2024 | Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN. |
| CVE-2024-24095 | CRITICAL | 9.8 | 0.6% | Feb 27, 2024 | Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection. |
| CVE-2024-22917 | HIGH | 8.6 | 0.7% | Feb 27, 2024 | SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute ar... |
| CVE-2024-27356 | HIGH | 7.5 | 23.9% | Feb 27, 2024 | An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially ... |
| CVE-2024-25166 | MEDIUM | 6.1 | 0.5% | Feb 27, 2024 | Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfil... |
| CVE-2024-24720 | MEDIUM | 5.3 | 0.5% | Feb 27, 2024 | An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information ... |
| CVE-2024-22544 | HIGH | 8 | 9.3% | Feb 27, 2024 | An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbi... |
| CVE-2024-22543 | MEDIUM | 6.1 | 1.2% | Feb 27, 2024 | An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges ... |
| CVE-2024-24721 | MEDIUM | 6.5 | 0.3% | Feb 27, 2024 | An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute ... |
| CVE-2024-25247 | CRITICAL | 9.8 | 0.6% | Feb 26, 2024 | SQL Injection vulnerability in /app/api/controller/Store.php in Niushop B2B2C V5 allows attackers to run arbitrary SQL c... |
| CVE-2024-27093 | HIGH | 7.5 | 0.6% | Feb 26, 2024 | Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to re... |
| CVE-2024-25751 | CRITICAL | 9.8 | 1.0% | Feb 26, 2024 | A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote... |
| CVE-2024-25248 | CRITICAL | 9.8 | 0.6% | Feb 26, 2024 | SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary S... |
| CVE-2024-27089 | — | — | — | Feb 26, 2024 | Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not in the allowed sc... |
| CVE-2024-26149 | MEDIUM | 5.3 | 0.5% | Feb 26, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified... |
| CVE-2024-24564 | MEDIUM | 5.3 | 0.6% | Feb 26, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star... |
| CVE-2024-24528 | — | — | — | Feb 26, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now