2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32488 | HIGH | 7.8 | 0.2% | Apr 15, 2024 | In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak p... |
| CVE-2024-2739 | HIGH | 8.7 | 0.3% | Apr 15, 2024 | The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers... |
| CVE-2024-1755 | HIGH | 8.8 | 0.4% | Apr 15, 2024 | The NPS computy WordPress plugin through 2.7.5 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2024-0399 | HIGH | 8.1 | 2.9% | Apr 15, 2024 | The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before ... |
| CVE-2024-3778 | HIGH | 7.2 | 0.6% | Apr 15, 2024 | The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attacker... |
| CVE-2024-3775 | HIGH | 7.5 | 0.4% | Apr 15, 2024 | aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user inpu... |
| CVE-2024-3767 | HIGH | 8.8 | 0.8% | Apr 15, 2024 | A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code ... |
| CVE-2024-1655 | HIGH | 8.8 | 2.0% | Apr 15, 2024 | Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to... |
| CVE-2024-3772 | HIGH | 7.5 | 0.9% | Apr 15, 2024 | Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service vi... |
| CVE-2024-29843 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-29842 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-29841 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-29840 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-29839 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access contr... |
| CVE-2024-29838 | HIGH | 7.5 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, a... |
| CVE-2024-29837 | HIGH | 8.8 | 0.5% | Apr 15, 2024 | The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing ... |
| CVE-2024-32487 | HIGH | 8.6 | 0.6% | Apr 13, 2024 | less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandle... |
| CVE-2024-3736 | HIGH | 7.5 | 0.9% | Apr 13, 2024 | A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulne... |
| CVE-2024-3719 | HIGH | 8.8 | 0.6% | Apr 13, 2024 | A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. This affec... |
| CVE-2024-28869 | HIGH | 7.5 | 1.0% | Apr 12, 2024 | Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint w... |
| CVE-2024-32019 | HIGH | 8.8 | 1.2% | Apr 12, 2024 | Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of t... |
| CVE-2024-32005 | HIGH | 8.2 | 0.8% | Apr 12, 2024 | NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component ... |
| CVE-2024-32003 | HIGH | 8.8 | 0.7% | Apr 12, 2024 | wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin ... |
| CVE-2024-29023 | HIGH | 7.2 | 0.8% | Apr 12, 2024 | Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software... |
| CVE-2024-29022 | HIGH | 8.8 | 0.7% | Apr 12, 2024 | Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now