2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34145 | HIGH | 8.8 | 1.0% | May 2, 2024 | A sandbox bypass vulnerability involving sandbox-defined classes that shadow specific non-sandbox-defined classes in Jen... |
| CVE-2024-33303 | HIGH | 8.2 | 0.5% | May 2, 2024 | SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users. |
| CVE-2024-30251 | HIGH | 7.5 | 1.1% | May 2, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can sen... |
| CVE-2024-23462 | HIGH | 7.5 | 0.2% | May 2, 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of se... |
| CVE-2024-33911 | HIGH | 7.2 | 1.1% | May 2, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Ma... |
| CVE-2024-32114 | HIGH | 8.8 | 6.9% | May 2, 2024 | In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and... |
| CVE-2024-3476 | HIGH | 8.8 | 0.4% | May 2, 2024 | The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow atta... |
| CVE-2024-3475 | HIGH | 7.5 | 0.3% | May 2, 2024 | The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow atta... |
| CVE-2024-3474 | HIGH | 8.8 | 0.4% | May 2, 2024 | The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow at... |
| CVE-2024-33423 | HIGH | 7.4 | 0.6% | May 1, 2024 | Cross-Site Scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary we... |
| CVE-2024-33306 | HIGH | 7.4 | 0.7% | May 1, 2024 | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter i... |
| CVE-2024-33430 | HIGH | 8.8 | 1.4% | May 1, 2024 | An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ... |
| CVE-2024-33429 | HIGH | 7.1 | 1.1% | May 1, 2024 | Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary cod... |
| CVE-2024-33428 | HIGH | 8.8 | 1.2% | May 1, 2024 | Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code ... |
| CVE-2024-33300 | HIGH | 7.3 | 0.6% | May 1, 2024 | Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows ... |
| CVE-2024-33292 | HIGH | 8.2 | 0.5% | May 1, 2024 | SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the i... |
| CVE-2024-29011 | HIGH | 7.5 | 0.9% | May 1, 2024 | Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects G... |
| CVE-2024-26504 | HIGH | 8.8 | 0.5% | May 1, 2024 | An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst pa... |
| CVE-2024-25458 | HIGH | 7.5 | 0.6% | May 1, 2024 | An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0... |
| CVE-2024-25355 | HIGH | 7.5 | 0.6% | May 1, 2024 | s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component. |
| CVE-2024-24313 | HIGH | 7.5 | 0.6% | May 1, 2024 | An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Mode... |
| CVE-2024-24312 | HIGH | 7.5 | 0.5% | May 1, 2024 | SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive infor... |
| CVE-2024-32212 | HIGH | 8.1 | 0.7% | May 1, 2024 | SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute ar... |
| CVE-2024-29010 | HIGH | 7.1 | 0.6% | May 1, 2024 | The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially... |
| CVE-2024-33517 | HIGH | 7.5 | 0.6% | May 1, 2024 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now