2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35247 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcoun... |
| CVE-2024-34030 | MEDIUM | 4.7 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocati... |
| CVE-2024-33847 | MEDIUM | 5.5 | 0.2% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on... |
| CVE-2024-32936 | MEDIUM | 4.7 | 0.1% | Jun 24, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting... |
| CVE-2024-3264 | MEDIUM | 5.3 | 0.2% | Jun 24, 2024 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows S... |
| CVE-2024-37233 | MEDIUM | 4.3 | 0.4% | Jun 24, 2024 | Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This is... |
| CVE-2024-36038 | MEDIUM | 6.3 | 1.4% | Jun 24, 2024 | Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerabi... |
| CVE-2024-4754 | MEDIUM | 5.4 | 0.2% | Jun 24, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM... |
| CVE-2024-27136 | MEDIUM | 6.1 | 59.4% | Jun 24, 2024 | XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser... |
| CVE-2024-4900 | MEDIUM | 6.1 | 0.3% | Jun 24, 2024 | The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contr... |
| CVE-2024-4899 | MEDIUM | 5 | 0.3% | Jun 24, 2024 | The SEOPress WordPress plugin before 7.8 does not sanitise and escape some of its Post settings, which could allow high... |
| CVE-2024-4499 | MEDIUM | 6.3 | 0.2% | Jun 24, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax ... |
| CVE-2024-39337 | MEDIUM | 6.5 | 0.3% | Jun 24, 2024 | Click Studios Passwordstate Core before 9.8 build 9858 allows Authentication Bypass. |
| CVE-2024-39334 | MEDIUM | 6.5 | 0.4% | Jun 23, 2024 | MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides prepared XML data. When a... |
| CVE-2024-6273 | MEDIUM | 6.1 | 0.6% | Jun 23, 2024 | A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by ... |
| CVE-2024-6267 | MEDIUM | 4.8 | 0.5% | Jun 23, 2024 | A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected b... |
| CVE-2024-6252 | MEDIUM | 6.1 | 0.4% | Jun 22, 2024 | A vulnerability has been found in Zorlan SkyCaiji up to 2.8 and classified as problematic. Affected by this vulnerabilit... |
| CVE-2024-6251 | MEDIUM | 6.1 | 0.4% | Jun 22, 2024 | A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the... |
| CVE-2024-38379 | MEDIUM | 4.8 | 0.7% | Jun 22, 2024 | Apache Allura's neighborhood settings are vulnerable to a stored XSS attack. Only neighborhood admins can access these ... |
| CVE-2024-5596 | MEDIUM | 6.3 | 0.2% | Jun 22, 2024 | The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2024-4940 | MEDIUM | 6.1 | 1.0% | Jun 22, 2024 | An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows a... |
| CVE-2024-3593 | MEDIUM | 5.4 | 0.2% | Jun 22, 2024 | The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.... |
| CVE-2024-4874 | MEDIUM | 4.3 | 0.3% | Jun 22, 2024 | The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc... |
| CVE-2024-21517 | MEDIUM | 6.1 | 0.4% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirec... |
| CVE-2024-21516 | MEDIUM | 4.7 | 0.4% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now