2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24771 | MEDIUM | 5.9 | 0.6% | Feb 7, 2024 | Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-e... |
| CVE-2024-25201 | HIGH | 7.5 | 0.7% | Feb 7, 2024 | Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at sr... |
| CVE-2024-25200 | HIGH | 7.5 | 0.7% | Feb 7, 2024 | Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.... |
| CVE-2024-24189 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c. |
| CVE-2024-24188 | CRITICAL | 9.8 | 0.8% | Feb 7, 2024 | Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c. |
| CVE-2024-24186 | CRITICAL | 9.8 | 0.9% | Feb 7, 2024 | Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish... |
| CVE-2024-24133 | CRITICAL | 9.8 | 0.6% | Feb 7, 2024 | Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page. |
| CVE-2024-24131 | MEDIUM | 6.1 | 0.9% | Feb 7, 2024 | SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp... |
| CVE-2024-24130 | MEDIUM | 6.1 | 0.4% | Feb 7, 2024 | Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability vi... |
| CVE-2024-1118 | HIGH | 8.8 | 0.7% | Feb 7, 2024 | The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute ... |
| CVE-2024-1110 | MEDIUM | 5.3 | 0.5% | Feb 7, 2024 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-1109 | MEDIUM | 5.3 | 0.6% | Feb 7, 2024 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2024-24311 | HIGH | 7.5 | 0.7% | Feb 7, 2024 | Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for Pr... |
| CVE-2024-24304 | HIGH | 7.5 | 0.5% | Feb 7, 2024 | In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical info... |
| CVE-2024-24303 | CRITICAL | 9.8 | 0.7% | Feb 7, 2024 | SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before versio... |
| CVE-2024-1079 | MEDIUM | 5.3 | 0.5% | Feb 7, 2024 | The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th... |
| CVE-2024-1078 | MEDIUM | 4.3 | 0.4% | Feb 7, 2024 | The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-0977 | MEDIUM | 5.4 | 0.3% | Feb 7, 2024 | The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerabl... |
| CVE-2024-1055 | MEDIUM | 5.4 | 0.4% | Feb 7, 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored... |
| CVE-2024-1037 | MEDIUM | 6.1 | 0.6% | Feb 7, 2024 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2024-0628 | LOW | 3.8 | 0.4% | Feb 7, 2024 | The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu... |
| CVE-2024-0256 | MEDIUM | 5.4 | 0.3% | Feb 7, 2024 | The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Se... |
| CVE-2024-23447 | MEDIUM | 6.5 | 0.4% | Feb 7, 2024 | An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions ... |
| CVE-2024-23446 | MEDIUM | 6.5 | 0.5% | Feb 7, 2024 | An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DL... |
| CVE-2024-24810 | HIGH | 7.8 | 0.2% | Feb 7, 2024 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folde... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now