2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22720 | MEDIUM | 4.8 | 0.4% | Jan 24, 2024 | Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature. |
| CVE-2024-23641 | HIGH | 7.5 | 0.8% | Jan 24, 2024 | SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/h... |
| CVE-2024-22229 | MEDIUM | 4.3 | 0.3% | Jan 24, 2024 | Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated atta... |
| CVE-2024-22725 | MEDIUM | 6.1 | 0.4% | Jan 24, 2024 | Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability w... |
| CVE-2024-22651 | CRITICAL | 9.8 | 20.2% | Jan 24, 2024 | There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmwa... |
| CVE-2024-22141 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue af... |
| CVE-2024-22154 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects Sal... |
| CVE-2024-22309 | CRITICAL | 9.8 | 0.5% | Jan 24, 2024 | Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from... |
| CVE-2024-22308 | MEDIUM | 6.1 | 0.3% | Jan 24, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affec... |
| CVE-2024-22301 | HIGH | 7.5 | 0.4% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This i... |
| CVE-2024-22294 | HIGH | 7.5 | 0.5% | Jan 24, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This... |
| CVE-2024-22284 | CRITICAL | 9.8 | 0.6% | Jan 24, 2024 | Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/... |
| CVE-2024-22152 | HIGH | 7.2 | 0.5% | Jan 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This is... |
| CVE-2024-22135 | HIGH | 7.2 | 0.5% | Jan 24, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Order Export & Order Import for WooCommerce.T... |
| CVE-2024-22134 | MEDIUM | 6.5 | 0.3% | Jan 24, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affe... |
| CVE-2024-0854 | MEDIUM | 5.4 | 0.4% | Jan 24, 2024 | URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manag... |
| CVE-2024-0665 | MEDIUM | 6.1 | 0.5% | Jan 24, 2024 | The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all... |
| CVE-2024-22372 | MEDIUM | 6.8 | 0.8% | Jan 24, 2024 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat... |
| CVE-2024-22366 | MEDIUM | 6.8 | 0.3% | Jan 24, 2024 | Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug... |
| CVE-2024-22380 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development ... |
| CVE-2024-21796 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creat... |
| CVE-2024-21765 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 a... |
| CVE-2024-23638 | MEDIUM | 6.5 | 60.1% | Jan 24, 2024 | Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable ... |
| CVE-2024-23633 | MEDIUM | 6.1 | 0.6% | Jan 24, 2024 | Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote w... |
| CVE-2024-23453 | MEDIUM | 5.5 | 0.2% | Jan 24, 2024 | Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retri... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now