2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34928 | HIGH | 7.3 | 0.3% | May 23, 2024 | A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web-Based School Management Sys... |
| CVE-2024-2301 | HIGH | 7.6 | 0.3% | May 23, 2024 | Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack via the web management... |
| CVE-2024-4471 | HIGH | 8 | 0.6% | May 23, 2024 | The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up t... |
| CVE-2024-34060 | HIGH | 8.8 | 1.0% | May 23, 2024 | IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-ev... |
| CVE-2024-26139 | HIGH | 8.1 | 0.4% | May 23, 2024 | OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observ... |
| CVE-2024-4779 | HIGH | 8.8 | 0.5% | May 23, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injecti... |
| CVE-2024-35186 | HIGH | 8.8 | 0.8% | May 23, 2024 | gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to... |
| CVE-2024-30280 | HIGH | 7.8 | 6.6% | May 23, 2024 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when ... |
| CVE-2024-30279 | HIGH | 7.8 | 5.9% | May 23, 2024 | Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that... |
| CVE-2024-4835 | HIGH | 8.2 | 0.8% | May 23, 2024 | A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By ... |
| CVE-2024-36013 | HIGH | 8.8 | 0.5% | May 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_... |
| CVE-2024-36012 | HIGH | 7.8 | 0.2% | May 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do... |
| CVE-2024-2038 | HIGH | 7.5 | 0.5% | May 23, 2024 | The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthori... |
| CVE-2024-4388 | HIGH | 7.5 | 0.7% | May 23, 2024 | This does not validate a path generated with user input when downloading files, allowing unauthenticated user to downlo... |
| CVE-2024-4347 | HIGH | 7.2 | 0.9% | May 23, 2024 | The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2... |
| CVE-2024-3594 | HIGH | 8.7 | 0.5% | May 23, 2024 | The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-4662 | HIGH | 8.8 | 0.9% | May 23, 2024 | The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8... |
| CVE-2024-4978 | HIGH | 8.4 | 26.9% | May 23, 2024 | Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected... |
| CVE-2024-29853 | HIGH | 7.8 | 0.2% | May 22, 2024 | An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. |
| CVE-2024-29851 | HIGH | 7.2 | 0.9% | May 22, 2024 | Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. |
| CVE-2024-29850 | HIGH | 8.8 | 0.8% | May 22, 2024 | Veeam Backup Enterprise Manager allows account takeover via NTLM relay. |
| CVE-2024-4454 | HIGH | 7.8 | 0.4% | May 22, 2024 | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allo... |
| CVE-2024-4453 | HIGH | 7.8 | 1.6% | May 22, 2024 | GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2024-27264 | HIGH | 7.8 | 0.1% | May 22, 2024 | IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual... |
| CVE-2024-21791 | HIGH | 7.2 | 2.2% | May 22, 2024 | Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL Injection in lockout history option. Note: Non-admin user... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now