2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5348 | HIGH | 8.8 | 0.8% | Jun 1, 2024 | The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi... |
| CVE-2024-3821 | HIGH | 7.3 | 0.3% | Jun 1, 2024 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unau... |
| CVE-2024-4958 | HIGH | 7.1 | 0.3% | Jun 1, 2024 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ... |
| CVE-2024-3564 | HIGH | 8.8 | 0.6% | Jun 1, 2024 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to... |
| CVE-2024-5138 | HIGH | 8.1 | 0.8% | May 31, 2024 | The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged a... |
| CVE-2024-34009 | HIGH | 7.5 | 0.4% | May 31, 2024 | Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not ... |
| CVE-2024-34008 | HIGH | 8.8 | 0.3% | May 31, 2024 | Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk. |
| CVE-2024-34007 | HIGH | 8.8 | 0.3% | May 31, 2024 | The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged o... |
| CVE-2024-36844 | HIGH | 7.5 | 0.6% | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows atta... |
| CVE-2024-36843 | HIGH | 7.5 | 0.8% | May 31, 2024 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. |
| CVE-2024-34001 | HIGH | 8.4 | 0.3% | May 31, 2024 | Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk. |
| CVE-2024-5564 | HIGH | 8.1 | 1.2% | May 31, 2024 | A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManage... |
| CVE-2024-23316 | HIGH | 8.8 | 0.5% | May 31, 2024 | HTTP request desynchronization in Ping Identity PingAccess, all versions prior to 8.0.1 affected allows an attacker to s... |
| CVE-2024-29848 | HIGH | 7.2 | 64.4% | May 31, 2024 | An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, pri... |
| CVE-2024-29846 | HIGH | 8 | 8.5% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29830 | HIGH | 8 | 8.5% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29829 | HIGH | 8 | 8.2% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29828 | HIGH | 8 | 8.5% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attac... |
| CVE-2024-29827 | HIGH | 8.8 | 71.7% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29826 | HIGH | 8.8 | 99.9% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29825 | HIGH | 8.8 | 99.9% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29824 | HIGH | 8.8 | 100.0% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29823 | HIGH | 8.8 | 99.9% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-29822 | HIGH | 8.8 | 64.4% | May 31, 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated att... |
| CVE-2024-22059 | HIGH | 8.8 | 1.1% | May 31, 2024 | A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/mod... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now