2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29121 | HIGH | 7.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Firassaidi WooComm... |
| CVE-2024-29116 | HIGH | 7.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IconicWP WooThumbs... |
| CVE-2024-29110 | HIGH | 7.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pauple Table & Con... |
| CVE-2024-29142 | HIGH | 7.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebberZone Better ... |
| CVE-2024-29139 | HIGH | 7.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Tilly MyCurat... |
| CVE-2024-29136 | HIGH | 8.8 | 0.6% | Mar 19, 2024 | Deserialization of Untrusted Data vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through... |
| CVE-2024-29135 | HIGH | 8.8 | 0.7% | Mar 19, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: fr... |
| CVE-2024-2635 | HIGH | 7.3 | 0.4% | Mar 19, 2024 | The configuration pages available are not intended to be placed on an Internet facing web server, as they expose file p... |
| CVE-2024-2632 | HIGH | 7.5 | 0.5% | Mar 19, 2024 | A Information Exposure Vulnerability has been found on Meta4 HR. This vulnerability allows an attacker to obtain a lot o... |
| CVE-2024-2614 | HIGH | 8.8 | 0.9% | Mar 19, 2024 | Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence ... |
| CVE-2024-2613 | HIGH | 7.5 | 0.5% | Mar 19, 2024 | Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption a... |
| CVE-2024-2612 | HIGH | 8.1 | 1.0% | Mar 19, 2024 | If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or po... |
| CVE-2024-2608 | HIGH | 8.4 | 0.4% | Mar 19, 2024 | `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experience... |
| CVE-2024-2607 | HIGH | 8.1 | 1.1% | Mar 19, 2024 | Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue onl... |
| CVE-2024-24042 | HIGH | 8.8 | 1.4% | Mar 19, 2024 | Directory Traversal vulnerability in Devan-Kerman ARRP v.0.8.1 and before allows a remote attacker to execute arbitrary ... |
| CVE-2024-26369 | HIGH | 7.5 | 0.6% | Mar 19, 2024 | An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal a... |
| CVE-2024-22017 | HIGH | 7.3 | 0.9% | Mar 19, 2024 | setuid() does not affect libuv's internal io_uring operations if initialized before the call to setuid(). This allows th... |
| CVE-2024-28865 | HIGH | 7.5 | 0.6% | Mar 18, 2024 | django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciou... |
| CVE-2024-28248 | HIGH | 7.2 | 0.6% | Mar 18, 2024 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 an... |
| CVE-2024-21661 | HIGH | 7.5 | 1.2% | Mar 18, 2024 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, a... |
| CVE-2024-0858 | HIGH | 8.8 | 0.4% | Mar 18, 2024 | The Innovs HR WordPress plugin through 1.0.3.4 does not have CSRF checks in some places, which could allow attackers to ... |
| CVE-2024-0780 | HIGH | 8.8 | 0.8% | Mar 18, 2024 | The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation when reset... |
| CVE-2024-0779 | HIGH | 8.8 | 0.4% | Mar 18, 2024 | The Enjoy Social Feed plugin for WordPress website WordPress plugin through 6.2.2 does not have authorisation and CSRF i... |
| CVE-2024-20761 | HIGH | 7.8 | 0.4% | Mar 18, 2024 | Animate versions 24.0, 23.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbi... |
| CVE-2024-20754 | HIGH | 7.8 | 0.3% | Mar 18, 2024 | Lightroom Desktop versions 7.1.2 and earlier are affected by an Untrusted Search Path vulnerability that could result in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now