2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-45270 | MEDIUM | 4.3 | 0.2% | Sep 2, 2024 | WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero ... |
| CVE-2024-45269 | MEDIUM | 4.3 | 0.3% | Sep 2, 2024 | WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carou... |
| CVE-2024-8370 | MEDIUM | 5.4 | 0.4% | Sep 1, 2024 | A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the... |
| CVE-2024-45509 | MEDIUM | 6.5 | 0.4% | Sep 1, 2024 | In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in t... |
| CVE-2024-5053 | MEDIUM | 4.3 | 0.4% | Sep 1, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-8367 | MEDIUM | 5.1 | 0.5% | Sep 1, 2024 | A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a... |
| CVE-2024-8366 | MEDIUM | 4.7 | 0.5% | Aug 31, 2024 | A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This a... |
| CVE-2024-44946 | MEDIUM | 5.5 | 0.8% | Aug 31, 2024 | In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. ... |
| CVE-2024-8108 | MEDIUM | 5.4 | 0.4% | Aug 31, 2024 | The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in ... |
| CVE-2024-0111 | MEDIUM | 4.4 | 0.2% | Aug 31, 2024 | NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect ... |
| CVE-2024-8276 | MEDIUM | 5.4 | 0.4% | Aug 31, 2024 | The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2024-39579 | MEDIUM | 6.7 | 0.2% | Aug 31, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local... |
| CVE-2024-39578 | MEDIUM | 6.3 | 0.2% | Aug 31, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. ... |
| CVE-2024-5212 | MEDIUM | 6.1 | 0.4% | Aug 31, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ paramet... |
| CVE-2024-3886 | MEDIUM | 6.1 | 0.4% | Aug 31, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ paramet... |
| CVE-2024-8006 | MEDIUM | 4.4 | 0.2% | Aug 31, 2024 | Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture ... |
| CVE-2024-45304 | MEDIUM | 6.5 | 0.5% | Aug 31, 2024 | Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability ... |
| CVE-2024-6585 | MEDIUM | 5.4 | 0.5% | Aug 30, 2024 | Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionali... |
| CVE-2024-8285 | MEDIUM | 5.9 | 0.4% | Aug 30, 2024 | A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured co... |
| CVE-2024-44684 | MEDIUM | 6.1 | 0.2% | Aug 30, 2024 | TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "C... |
| CVE-2024-44683 | MEDIUM | 6.1 | 0.2% | Aug 30, 2024 | Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php. |
| CVE-2024-44682 | MEDIUM | 6.1 | 0.3% | Aug 30, 2024 | ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing ... |
| CVE-2024-21658 | MEDIUM | 4.3 | 0.4% | Aug 30, 2024 | discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topi... |
| CVE-2024-8235 | MEDIUM | 6.2 | 0.2% | Aug 30, 2024 | A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corne... |
| CVE-2024-45047 | MEDIUM | 6.1 | 0.3% | Aug 30, 2024 | svelte performance oriented web framework. A potential mXSS vulnerability exists in Svelte for versions up to but not in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now