2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4185 | HIGH | 8.1 | 0.9% | Apr 30, 2024 | The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authenticat... |
| CVE-2024-2663 | HIGH | 8.3 | 0.4% | Apr 30, 2024 | The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and i... |
| CVE-2024-1895 | HIGH | 7.5 | 0.9% | Apr 30, 2024 | The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object I... |
| CVE-2024-4225 | HIGH | 7.6 | 0.3% | Apr 30, 2024 | Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), b... |
| CVE-2024-31837 | HIGH | 8.4 | 0.2% | Apr 30, 2024 | DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE... |
| CVE-2024-34050 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<... |
| CVE-2024-34049 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0... |
| CVE-2024-34046 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParam... |
| CVE-2024-34045 | HIGH | 7.5 | 0.5% | Apr 30, 2024 | The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[... |
| CVE-2024-27518 | HIGH | 7.8 | 0.6% | Apr 29, 2024 | An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges ... |
| CVE-2024-33271 | HIGH | 7.5 | 0.5% | Apr 29, 2024 | An issue in FME Modules eventsmanager before 4.4.0 allows an attacker to obtain sensitive information from the ps_custom... |
| CVE-2024-31801 | HIGH | 7.5 | 1.1% | Apr 29, 2024 | Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive informat... |
| CVE-2024-0840 | HIGH | 8.8 | 0.9% | Apr 29, 2024 | The Grandstream UCM Series IP PBX before firmware version 1.0.20.52 is affected by a parameter injection vulnerability i... |
| CVE-2024-33443 | HIGH | 7.1 | 0.7% | Apr 29, 2024 | An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsControll... |
| CVE-2024-33438 | HIGH | 8 | 1.1% | Apr 29, 2024 | File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted ... |
| CVE-2024-33338 | HIGH | 7.3 | 1.0% | Apr 29, 2024 | Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a cr... |
| CVE-2024-31821 | HIGH | 8 | 1.1% | Apr 29, 2024 | SQL Injection vulnerability in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows... |
| CVE-2024-28320 | HIGH | 7.6 | 0.5% | Apr 29, 2024 | Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate ... |
| CVE-2024-32493 | HIGH | 8.8 | 0.7% | Apr 29, 2024 | An issue was discovered in Znuny LTS 6.5.1 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in agent is able ... |
| CVE-2024-32492 | HIGH | 7.1 | 0.5% | Apr 29, 2024 | An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the exec... |
| CVE-2024-32269 | HIGH | 7.5 | 0.7% | Apr 29, 2024 | An issue in Yonganda YAD-LOJ V3.0.561 allows a remote attacker to cause a denial of service via a crafted packet. |
| CVE-2024-31621 | HIGH | 7.6 | 59.9% | Apr 29, 2024 | An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc... |
| CVE-2024-34010 | HIGH | 8.2 | 0.2% | Apr 29, 2024 | Local privilege escalation due to unquoted search path vulnerability. The following products are affected: Acronis Cyber... |
| CVE-2024-1969 | HIGH | 8.2 | 0.5% | Apr 29, 2024 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Secomea GateManager (webserver m... |
| CVE-2024-1579 | HIGH | 8.1 | 0.5% | Apr 29, 2024 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Secomea GateManager (Webserver module... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now