2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28850 | HIGH | 8.1 | 0.2% | Mar 25, 2024 | WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative u... |
| CVE-2024-28107 | HIGH | 8.8 | 1.0% | Mar 25, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection ... |
| CVE-2024-28105 | HIGH | 7.2 | 1.5% | Mar 25, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category imag... |
| CVE-2024-27299 | HIGH | 8.8 | 1.2% | Mar 25, 2024 | phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection v... |
| CVE-2024-30205 | HIGH | 7.1 | 0.5% | Mar 25, 2024 | In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23. |
| CVE-2024-30202 | HIGH | 7.8 | 1.1% | Mar 25, 2024 | In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.... |
| CVE-2024-28434 | HIGH | 7.6 | 0.7% | Mar 25, 2024 | The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg fil... |
| CVE-2024-28387 | HIGH | 7.5 | 0.4% | Mar 25, 2024 | An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt compone... |
| CVE-2024-25002 | HIGH | 8.8 | 1.2% | Mar 25, 2024 | Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access t... |
| CVE-2024-25964 | HIGH | 7.5 | 0.7% | Mar 25, 2024 | Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability. A remote unauthenticated at... |
| CVE-2024-24899 | HIGH | 7.2 | 1.7% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ao... |
| CVE-2024-24897 | HIGH | 8.1 | 1.4% | Mar 25, 2024 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Co... |
| CVE-2024-24892 | HIGH | 8.1 | 0.9% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Managemen... |
| CVE-2024-24890 | HIGH | 7.8 | 1.1% | Mar 25, 2024 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ga... |
| CVE-2024-21505 | HIGH | 7.5 | 0.7% | Mar 25, 2024 | Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format a... |
| CVE-2024-1962 | HIGH | 8.8 | 0.5% | Mar 25, 2024 | The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attac... |
| CVE-2024-29071 | HIGH | 8.8 | 0.4% | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at... |
| CVE-2024-28041 | HIGH | 8.8 | 0.6% | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary comm... |
| CVE-2024-29188 | HIGH | 7.9 | 0.2% | Mar 24, 2024 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action ... |
| CVE-2024-29187 | HIGH | 7.3 | 0.5% | Mar 24, 2024 | WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs... |
| CVE-2024-29194 | HIGH | 8.3 | 0.7% | Mar 24, 2024 | OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation o... |
| CVE-2024-30156 | HIGH | 7.5 | 3.7% | Mar 24, 2024 | Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, all... |
| CVE-2024-24725 | HIGH | 8.8 | 51.3% | Mar 23, 2024 | Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POS... |
| CVE-2024-23755 | HIGH | 8.8 | 1.1% | Mar 23, 2024 | ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is in... |
| CVE-2024-1603 | HIGH | 7.5 | 0.6% | Mar 23, 2024 | paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now