2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30458 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WOOCS – WooCommerce Currency Switcher.This issue affects W... |
| CVE-2024-30457 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issu... |
| CVE-2024-30456 | HIGH | 8.8 | 0.2% | Mar 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in realmag777 WPCS.This issue affects WPCS: from n/a through 1.2.0.1. |
| CVE-2024-2848 | HIGH | 7.5 | 0.7% | Mar 29, 2024 | The Responsive theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2024-3061 | HIGH | 7.2 | 0.8% | Mar 29, 2024 | The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a... |
| CVE-2024-1872 | HIGH | 8.8 | 0.9% | Mar 29, 2024 | The Button plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.27 via d... |
| CVE-2024-0913 | HIGH | 7.2 | 0.6% | Mar 29, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-28960 | HIGH | 8.2 | 0.8% | Mar 29, 2024 | An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA C... |
| CVE-2024-28714 | HIGH | 8.1 | 0.8% | Mar 28, 2024 | SQL Injection vulnerability in CRMEB_Java e-commerce system v.1.3.4 allows an attacker to execute arbitrary code via the... |
| CVE-2024-23727 | HIGH | 8.4 | 0.5% | Mar 28, 2024 | The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker ... |
| CVE-2024-3019 | HIGH | 8.8 | 1.0% | Mar 28, 2024 | A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowi... |
| CVE-2024-2947 | HIGH | 7.3 | 1.2% | Mar 28, 2024 | A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a comman... |
| CVE-2024-25963 | HIGH | 7.5 | 0.3% | Mar 28, 2024 | Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability... |
| CVE-2024-25960 | HIGH | 7.8 | 0.1% | Mar 28, 2024 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulner... |
| CVE-2024-25955 | HIGH | 8.8 | 1.4% | Mar 28, 2024 | Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot... |
| CVE-2024-25954 | HIGH | 7.5 | 0.6% | Mar 28, 2024 | Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A rem... |
| CVE-2024-25946 | HIGH | 8.8 | 1.4% | Mar 28, 2024 | Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot... |
| CVE-2024-31139 | HIGH | 8.1 | 0.5% | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector |
| CVE-2024-31136 | HIGH | 7.4 | 0.5% | Mar 28, 2024 | In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter |
| CVE-2024-30612 | HIGH | 8.1 | 0.7% | Mar 28, 2024 | Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from for... |
| CVE-2024-30604 | HIGH | 7.5 | 0.7% | Mar 28, 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function. |
| CVE-2024-30601 | HIGH | 8 | 0.7% | Mar 28, 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function. |
| CVE-2024-30600 | HIGH | 8 | 0.7% | Mar 28, 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function. |
| CVE-2024-30599 | HIGH | 8.8 | 0.7% | Mar 28, 2024 | Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function. |
| CVE-2024-0259 | HIGH | 7.3 | 0.3% | Mar 28, 2024 | Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now