2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0685 | CRITICAL | 9.8 | 0.8% | Feb 2, 2024 | The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second... |
| CVE-2024-22533 | CRITICAL | 9.8 | 1.0% | Feb 2, 2024 | Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incomi... |
| CVE-2024-22320 | HIGH | 8.8 | 73.4% | Feb 2, 2024 | IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the sys... |
| CVE-2024-22319 | CRITICAL | 9.8 | 76.4% | Feb 2, 2024 | IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remo... |
| CVE-2024-23746 | CRITICAL | 9.8 | 1.3% | Feb 2, 2024 | Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in ... |
| CVE-2024-22903 | HIGH | 8.8 | 1.9% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2024-22902 | CRITICAL | 9.8 | 1.1% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials. |
| CVE-2024-22901 | CRITICAL | 9.8 | 1.1% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials. |
| CVE-2024-22900 | HIGH | 8.8 | 1.9% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2024-22899 | HIGH | 8.8 | 2.4% | Feb 2, 2024 | Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via ... |
| CVE-2024-22779 | CRITICAL | 9.8 | 1.9% | Feb 2, 2024 | Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbit... |
| CVE-2024-21399 | HIGH | 8.3 | 1.2% | Feb 2, 2024 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2024-22096 | MEDIUM | 6.5 | 0.6% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to... |
| CVE-2024-22016 | HIGH | 7.8 | 0.2% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada ... |
| CVE-2024-21869 | MEDIUM | 5.5 | 0.2% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials i... |
| CVE-2024-21866 | MEDIUM | 5.3 | 0.4% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error me... |
| CVE-2024-21794 | MEDIUM | 5.4 | 0.3% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages t... |
| CVE-2024-21764 | CRITICAL | 9.8 | 0.6% | Feb 2, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may ... |
| CVE-2024-24756 | HIGH | 7.5 | 0.9% | Feb 1, 2024 | Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/`... |
| CVE-2024-23034 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary c... |
| CVE-2024-23033 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary co... |
| CVE-2024-23032 | MEDIUM | 6.1 | 0.5% | Feb 1, 2024 | Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code vi... |
| CVE-2024-23031 | MEDIUM | 6.1 | 0.4% | Feb 1, 2024 | Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr... |
| CVE-2024-22927 | MEDIUM | 6.1 | 1.0% | Feb 1, 2024 | Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitr... |
| CVE-2024-21852 | HIGH | 8.8 | 1.2% | Feb 1, 2024 | In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration fi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now