2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30533 | HIGH | 7.5 | 0.5% | Mar 31, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Techeshta Layouts for Elementor.This issue affects Layo... |
| CVE-2024-30489 | HIGH | 8.5 | 0.5% | Mar 31, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in loopus WP Cost Est... |
| CVE-2024-31094 | HIGH | 8.5 | 0.6% | Mar 31, 2024 | Deserialization of Untrusted Data vulnerability in Filter Custom Fields & Taxonomies Light.This issue affects Filter Cus... |
| CVE-2024-22353 | HIGH | 7.5 | 0.8% | Mar 31, 2024 | IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.4 is vulnerable to a denial of service, caused by sendi... |
| CVE-2024-3118 | HIGH | 8.8 | 0.8% | Mar 31, 2024 | A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some un... |
| CVE-2024-1522 | HIGH | 8.8 | 0.4% | Mar 30, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execut... |
| CVE-2024-3018 | HIGH | 8.8 | 0.8% | Mar 30, 2024 | The Essential Addons for Elementor plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and... |
| CVE-2024-3088 | HIGH | 7.3 | 0.8% | Mar 30, 2024 | A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. This a... |
| CVE-2024-2047 | HIGH | 8.8 | 1.5% | Mar 30, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2024-30441 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post G... |
| CVE-2024-30439 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BestWebSoft Limit ... |
| CVE-2024-30435 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH Nexter Bl... |
| CVE-2024-30431 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Boar... |
| CVE-2024-30462 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 HUSKY – Products Filter for WooCommerce (formerly WOOF).Th... |
| CVE-2024-30454 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.6.2. |
| CVE-2024-30449 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking Activities... |
| CVE-2024-30447 | HIGH | 7.1 | 0.4% | Mar 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative Solutions... |
| CVE-2024-25944 | HIGH | 7.5 | 0.8% | Mar 29, 2024 | Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacke... |
| CVE-2024-30645 | HIGH | 8 | 1.0% | Mar 29, 2024 | Tenda AC15V1.0 V15.03.20_multi has a command injection vulnerability via the deviceName parameter. |
| CVE-2024-30482 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Brice CAPOBIANCO Simple Revisions Delete.This issue affects Simple Re... |
| CVE-2024-30246 | HIGH | 7.1 | 0.6% | Mar 29, 2024 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious user could ... |
| CVE-2024-29904 | HIGH | 7.5 | 0.8% | Mar 29, 2024 | CodeIgniter is a PHP full-stack web framework A vulnerability was found in the Language class that allowed DoS attacks. ... |
| CVE-2024-29901 | HIGH | 8.1 | 0.7% | Mar 29, 2024 | The AuthKit library for Next.js provides helpers for authentication and session management using WorkOS & AuthKit with N... |
| CVE-2024-29900 | HIGH | 7.5 | 0.6% | Mar 29, 2024 | Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files... |
| CVE-2024-29686 | HIGH | 7.2 | 1.8% | Mar 29, 2024 | Server-side Template Injection (SSTI) vulnerability in Winter CMS v.1.2.3 allows a remote attacker to execute arbitrary ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now