2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24881 | MEDIUM | 6.1 | 0.4% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ... |
| CVE-2024-24880 | MEDIUM | 5.4 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apo... |
| CVE-2024-24879 | MEDIUM | 6.1 | 0.4% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre L... |
| CVE-2024-24886 | MEDIUM | 5.4 | 0.3% | Feb 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acowebs Product La... |
| CVE-2024-22464 | MEDIUM | 6.8 | 0.5% | Feb 8, 2024 | Dell EMC AppSync, versions from 4.2.0.0 to 4.6.0.0 including all Service Pack releases, contain an exposure of sensitiv... |
| CVE-2024-24034 | MEDIUM | 6.1 | 0.6% | Feb 8, 2024 | Setor Informatica S.I.L version 3.0 is vulnerable to Open Redirect via the hprinter parameter, allows remote attackers t... |
| CVE-2024-23452 | HIGH | 7.5 | 1.6% | Feb 8, 2024 | Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle re... |
| CVE-2024-1207 | CRITICAL | 9.8 | 3.2% | Feb 8, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmy... |
| CVE-2024-0965 | MEDIUM | 5.3 | 0.5% | Feb 8, 2024 | The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2024-24216 | CRITICAL | 9.8 | 1.3% | Feb 8, 2024 | Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection met... |
| CVE-2024-24091 | CRITICAL | 9.8 | 1.1% | Feb 8, 2024 | Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file up... |
| CVE-2024-0511 | MEDIUM | 4.3 | 0.2% | Feb 8, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2024-24202 | CRITICAL | 9.8 | 1.0% | Feb 8, 2024 | An arbitrary file upload vulnerability in /upgrade/control.php of ZenTao Community Edition v18.10, ZenTao Biz v8.10, and... |
| CVE-2024-25148 | HIGH | 8.1 | 0.5% | Feb 8, 2024 | In Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 be... |
| CVE-2024-25146 | MEDIUM | 5.3 | 0.6% | Feb 8, 2024 | Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 befor... |
| CVE-2024-25144 | MEDIUM | 6.5 | 0.6% | Feb 8, 2024 | The IFrame widget in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before u... |
| CVE-2024-24021 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, ... |
| CVE-2024-24017 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l... |
| CVE-2024-24014 | CRITICAL | 9.8 | 0.6% | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, l... |
| CVE-2024-24003 | CRITICAL | 9.8 | 0.8% | Feb 8, 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseRespon... |
| CVE-2024-22394 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific con... |
| CVE-2024-24350 | HIGH | 8.8 | 1.2% | Feb 8, 2024 | File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary... |
| CVE-2024-24026 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controll... |
| CVE-2024-24025 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileCo... |
| CVE-2024-24024 | CRITICAL | 9.8 | 0.7% | Feb 8, 2024 | An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.File... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now