2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1061 | CRITICAL | 9.8 | 11.1% | Jan 30, 2024 | The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerabilit... |
| CVE-2024-21803 | HIGH | 7.8 | 0.5% | Jan 30, 2024 | Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution ... |
| CVE-2024-22648 | MEDIUM | 5.3 | 0.6% | Jan 30, 2024 | A Blind SSRF vulnerability exists in the "Crawl Meta Data" functionality of SEO Panel version 4.10.0. This makes it poss... |
| CVE-2024-22647 | MEDIUM | 5.3 | 0.6% | Jan 30, 2024 | An user enumeration vulnerability was found in SEO Panel 4.10.0. This issue occurs during user authentication, where a d... |
| CVE-2024-22646 | MEDIUM | 5.3 | 0.6% | Jan 30, 2024 | An email address enumeration vulnerability exists in the password reset function of SEO Panel version 4.10.0. This allow... |
| CVE-2024-22643 | MEDIUM | 6.5 | 0.3% | Jan 30, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in SEO Panel version 4.10.0 allows remote attackers to perform unautho... |
| CVE-2024-1029 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. Affected by this issue is some unknow... |
| CVE-2024-21488 | CRITICAL | 9.8 | 3.2% | Jan 30, 2024 | Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_proce... |
| CVE-2024-1028 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by ... |
| CVE-2024-21840 | HIGH | 7.1 | 0.1% | Jan 30, 2024 | Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and... |
| CVE-2024-1027 | CRITICAL | 9.8 | 0.5% | Jan 30, 2024 | A vulnerability, which was classified as critical, was found in SourceCodester Facebook News Feed Like 1.0. Affected is ... |
| CVE-2024-22938 | HIGH | 7.8 | 0.3% | Jan 30, 2024 | Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate pri... |
| CVE-2024-22682 | — | — | — | Jan 30, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-1026 | MEDIUM | 6.1 | 0.3% | Jan 30, 2024 | A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown proce... |
| CVE-2024-1024 | MEDIUM | 6.1 | 0.3% | Jan 30, 2024 | A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnera... |
| CVE-2024-23829 | MEDIUM | 6.5 | 1.0% | Jan 29, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python H... |
| CVE-2024-23334 | HIGH | 7.5 | 76.9% | Jan 29, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and c... |
| CVE-2024-1022 | MEDIUM | 4.8 | 0.5% | Jan 29, 2024 | A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6... |
| CVE-2024-1021 | CRITICAL | 9.8 | 35.0% | Jan 29, 2024 | A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the ... |
| CVE-2024-1020 | MEDIUM | 6.1 | 0.6% | Jan 29, 2024 | A vulnerability classified as problematic was found in Rebuild up to 3.5.5. Affected by this vulnerability is the functi... |
| CVE-2024-24141 | CRITICAL | 9.8 | 1.1% | Jan 29, 2024 | Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter. |
| CVE-2024-24140 | HIGH | 7.2 | 1.2% | Jan 29, 2024 | Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.' |
| CVE-2024-24139 | HIGH | 7.2 | 1.2% | Jan 29, 2024 | Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter. |
| CVE-2024-24136 | MEDIUM | 6.1 | 0.6% | Jan 29, 2024 | The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cro... |
| CVE-2024-22570 | MEDIUM | 5.4 | 0.3% | Jan 29, 2024 | A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows atta... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now