2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4712 | HIGH | 7.8 | 0.4% | May 14, 2024 | An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl... |
| CVE-2024-4681 | HIGH | 7.2 | 1.0% | May 14, 2024 | A vulnerability, which was classified as critical, was found in Campcodes Legal Case Management System 1.0. Affected is ... |
| CVE-2024-4605 | HIGH | 8.8 | 0.9% | May 14, 2024 | The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 v... |
| CVE-2024-4545 | HIGH | 7.7 | 0.5% | May 14, 2024 | All versions of EnterpriseDB Postgres Advanced Server (EPAS) from 15.0 prior to 15.7.0 and from 16.0 prior to 16.3.0 ma... |
| CVE-2024-4441 | HIGH | 8.1 | 0.7% | May 14, 2024 | The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and incl... |
| CVE-2024-4423 | HIGH | 7.2 | 0.9% | May 14, 2024 | The access control in CemiPark software does not properly validate user-entered data, which allows the authentication by... |
| CVE-2024-4397 | HIGH | 8.8 | 1.0% | May 14, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file t... |
| CVE-2024-4129 | HIGH | 8.8 | 0.5% | May 14, 2024 | Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to... |
| CVE-2024-4068 | HIGH | 7.5 | 1.5% | May 14, 2024 | The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could le... |
| CVE-2024-4044 | HIGH | 7.8 | 14.7% | May 14, 2024 | A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may... |
| CVE-2024-3954 | HIGH | 8.8 | 0.7% | May 14, 2024 | The Ditty plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.1.38 via deserialization of... |
| CVE-2024-3940 | HIGH | 8.8 | 0.4% | May 14, 2024 | The reCAPTCHA Jetpack WordPress plugin through 0.2.2 does not have CSRF check in place when updating its settings, which... |
| CVE-2024-3903 | HIGH | 7.1 | 0.2% | May 14, 2024 | The Add Custom CSS and JS WordPress plugin through 1.20 does not have CSRF check in some places, and is missing sanitisa... |
| CVE-2024-3828 | HIGH | 8.8 | 0.6% | May 14, 2024 | The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. ... |
| CVE-2024-3809 | HIGH | 8.8 | 1.0% | May 14, 2024 | The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2024-3808 | HIGH | 8.8 | 1.0% | May 14, 2024 | The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and in... |
| CVE-2024-3807 | HIGH | 8.8 | 1.5% | May 14, 2024 | The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via 'por... |
| CVE-2024-3727 | HIGH | 8.3 | 1.3% | May 14, 2024 | A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authentica... |
| CVE-2024-3460 | HIGH | 7 | 0.3% | May 14, 2024 | In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened app... |
| CVE-2024-3459 | HIGH | 7.8 | 0.3% | May 14, 2024 | KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by... |
| CVE-2024-3055 | HIGH | 8.8 | 0.8% | May 14, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ... |
| CVE-2024-3037 | HIGH | 7.8 | 0.4% | May 14, 2024 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print... |
| CVE-2024-35205 | HIGH | 7.8 | 0.8% | May 14, 2024 | The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names befo... |
| CVE-2024-35204 | HIGH | 8.4 | 0.2% | May 14, 2024 | Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus lo... |
| CVE-2024-35166 | HIGH | 7.5 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Fileb... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now