2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0324 | HIGH | 7.5 | 2.4% | Feb 5, 2024 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2024-0255 | MEDIUM | 5.4 | 0.5% | Feb 5, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-recipe-text... |
| CVE-2024-0254 | MEDIUM | 5.4 | 0.5% | Feb 5, 2024 | The (Simply) Guest Author Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's post m... |
| CVE-2024-0221 | HIGH | 7.2 | 1.3% | Feb 5, 2024 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in ... |
| CVE-2024-24807 | MEDIUM | 4.8 | 0.5% | Feb 5, 2024 | Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue ... |
| CVE-2024-24574 | MEDIUM | 6.1 | 0.9% | Feb 5, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Unsafe echo of fi... |
| CVE-2024-24559 | MEDIUM | 5.3 | 0.3% | Feb 5, 2024 | Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `I... |
| CVE-2024-24543 | CRITICAL | 9.8 | 1.0% | Feb 5, 2024 | Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allo... |
| CVE-2024-22208 | MEDIUM | 6.5 | 0.7% | Feb 5, 2024 | phpMyFAQ is an Open Source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The 'sharing FAQ'... |
| CVE-2024-1052 | HIGH | 8 | 0.3% | Feb 5, 2024 | Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An a... |
| CVE-2024-0202 | MEDIUM | 5.9 | 0.3% | Feb 5, 2024 | A security vulnerability has been identified in the cryptlib cryptographic library when cryptlib is compiled with the su... |
| CVE-2024-22567 | HIGH | 8.8 | 17.8% | Feb 5, 2024 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/... |
| CVE-2024-22202 | MEDIUM | 6.5 | 0.6% | Feb 5, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. phpMyFAQ's user r... |
| CVE-2024-24396 | MEDIUM | 6.1 | 1.1% | Feb 5, 2024 | Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker... |
| CVE-2024-24267 | HIGH | 7.5 | 1.6% | Feb 5, 2024 | gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_b... |
| CVE-2024-24266 | HIGH | 7.5 | 1.3% | Feb 5, 2024 | gpac v2.2.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the dasher_configure_pid function at /src... |
| CVE-2024-24265 | HIGH | 7.5 | 1.3% | Feb 5, 2024 | gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_int... |
| CVE-2024-24263 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_lin... |
| CVE-2024-24262 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function a... |
| CVE-2024-24260 | HIGH | 7.5 | 0.7% | Feb 5, 2024 | media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function... |
| CVE-2024-24259 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry functi... |
| CVE-2024-24258 | HIGH | 7.5 | 1.1% | Feb 5, 2024 | freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. |
| CVE-2024-0953 | MEDIUM | 6.1 | 0.3% | Feb 5, 2024 | When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the pag... |
| CVE-2024-24469 | HIGH | 8.8 | 0.5% | Feb 5, 2024 | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-24468 | HIGH | 8.8 | 0.5% | Feb 5, 2024 | Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via th... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now