2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24926 | HIGH | 8.8 | 1.1% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress T... |
| CVE-2024-24797 | CRITICAL | 9.8 | 0.6% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue... |
| CVE-2024-24796 | HIGH | 8.8 | 0.5% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooComme... |
| CVE-2024-23513 | CRITICAL | 9.8 | 0.5% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. |
| CVE-2024-25100 | CRITICAL | 9.8 | 0.8% | Feb 12, 2024 | Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue ... |
| CVE-2024-24889 | MEDIUM | 6.1 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Geek Code Lab All ... |
| CVE-2024-24933 | MEDIUM | 6.1 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prasidhda Malla Ho... |
| CVE-2024-24932 | MEDIUM | 6.1 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Grou... |
| CVE-2024-24931 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swadeshswain Befor... |
| CVE-2024-24930 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes.Com Butt... |
| CVE-2024-24928 | MEDIUM | 5.4 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arunas Liuiza Cont... |
| CVE-2024-24927 | MEDIUM | 6.1 | 0.3% | Feb 12, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brook... |
| CVE-2024-25744 | HIGH | 8.8 | 0.3% | Feb 12, 2024 | In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is relate... |
| CVE-2024-25741 | MEDIUM | 5.5 | 0.3% | Feb 12, 2024 | printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep... |
| CVE-2024-25740 | MEDIUM | 5.5 | 0.2% | Feb 12, 2024 | A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOC... |
| CVE-2024-25739 | MEDIUM | 5.5 | 0.2% | Feb 12, 2024 | create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes, and cr... |
| CVE-2024-1433 | LOW | 3.7 | 0.8% | Feb 11, 2024 | A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the f... |
| CVE-2024-25728 | HIGH | 7.5 | 0.7% | Feb 11, 2024 | ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configur... |
| CVE-2024-25419 | HIGH | 8.8 | 0.3% | Feb 11, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_men... |
| CVE-2024-25418 | HIGH | 8.8 | 0.3% | Feb 11, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_men... |
| CVE-2024-25417 | HIGH | 8.8 | 0.3% | Feb 11, 2024 | flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_transl... |
| CVE-2024-1151 | MEDIUM | 5.5 | 0.3% | Feb 11, 2024 | A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive ope... |
| CVE-2024-21875 | MEDIUM | 6.5 | 0.5% | Feb 11, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in Badge leading to a denial of service attack.Team H... |
| CVE-2024-25722 | CRITICAL | 9.8 | 0.6% | Feb 11, 2024 | qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection. |
| CVE-2024-25718 | CRITICAL | 9.8 | 0.7% | Feb 11, 2024 | In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which int... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now