2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7135 | MEDIUM | 6.5 | 2.7% | Jul 31, 2024 | The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ... |
| CVE-2024-6725 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Word... |
| CVE-2024-7310 | MEDIUM | 6.1 | 0.4% | Jul 31, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vuln... |
| CVE-2024-7309 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This af... |
| CVE-2024-2508 | MEDIUM | 5.3 | 0.4% | Jul 31, 2024 | The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2024-7303 | MEDIUM | 5.4 | 0.5% | Jul 31, 2024 | A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. Thi... |
| CVE-2024-7264 | MEDIUM | 6.5 | 16.2% | Jul 31, 2024 | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an... |
| CVE-2024-7300 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file ... |
| CVE-2024-7299 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issu... |
| CVE-2024-6412 | MEDIUM | 6.5 | 0.3% | Jul 31, 2024 | The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2024-6408 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow hig... |
| CVE-2024-6272 | MEDIUM | 6.1 | 0.3% | Jul 31, 2024 | The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-6165 | MEDIUM | 4.8 | 0.4% | Jul 31, 2024 | The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-7285 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problemat... |
| CVE-2024-39947 | MEDIUM | 6.5 | 0.5% | Jul 31, 2024 | A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker... |
| CVE-2024-39945 | MEDIUM | 4.9 | 0.5% | Jul 31, 2024 | A vulnerability has been found in Dahua products. After obtaining the administrator's username and password, the attack... |
| CVE-2024-7284 | MEDIUM | 5.4 | 0.4% | Jul 31, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0.... |
| CVE-2024-37281 | MEDIUM | 6.5 | 0.4% | Jul 30, 2024 | An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a larg... |
| CVE-2024-5901 | MEDIUM | 5.4 | 0.4% | Jul 30, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widge... |
| CVE-2024-5250 | MEDIUM | 5.3 | 0.3% | Jul 30, 2024 | In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations |
| CVE-2024-41443 | MEDIUM | 5.5 | 0.4% | Jul 30, 2024 | A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial ... |
| CVE-2024-41440 | MEDIUM | 6.2 | 0.8% | Jul 30, 2024 | A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (D... |
| CVE-2024-41439 | MEDIUM | 5.5 | 0.4% | Jul 30, 2024 | A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Den... |
| CVE-2024-41438 | MEDIUM | 6.2 | 0.8% | Jul 30, 2024 | A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a De... |
| CVE-2024-41437 | MEDIUM | 5.5 | 0.4% | Jul 30, 2024 | A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now