2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-14028 | MEDIUM | 6.5 | 0.2% | Mar 27, 2026 | Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects... |
| CVE-2024-46879 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in... |
| CVE-2024-46878 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and ea... |
| CVE-2024-51226 | MEDIUM | 6.1 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Recor... |
| CVE-2024-51225 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Man... |
| CVE-2024-51224 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Recor... |
| CVE-2024-51223 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag... |
| CVE-2024-51222 | MEDIUM | 4.8 | 0.2% | Mar 23, 2026 | A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Manag... |
| CVE-2024-13785 | MEDIUM | 5.6 | 0.3% | Mar 21, 2026 | The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortc... |
| CVE-2024-31119 | MEDIUM | 5.9 | 0.2% | Mar 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Vasilis Triantafyl... |
| CVE-2024-42210 | MEDIUM | 5.4 | 0.2% | Mar 19, 2026 | A Stored cross-site scripting (XSS) vulnerability affects HCL Unica Marketing Operations v12.1.8 and lower. Stored cros... |
| CVE-2024-14025 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | An SQL injection vulnerability has been reported to affect Video Station. If an attacker gains local network access who ... |
| CVE-2024-14024 | MEDIUM | 6.7 | 0.1% | Mar 11, 2026 | An improper certificate validation vulnerability has been reported to affect Video Station. If an attacker gains local n... |
| CVE-2024-14027 | MEDIUM | 5.5 | 0.3% | Mar 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/xattr: missing fdput() in fremovexattr error pat... |
| CVE-2024-35644 | MEDIUM | 5.9 | 0.2% | Mar 6, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pascal Birc... |
| CVE-2024-43035 | MEDIUM | 5.8 | 2.4% | Mar 5, 2026 | Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V... |
| CVE-2024-55025 | MEDIUM | 6.5 | 0.3% | Mar 3, 2026 | Incorrect access control in the VNC component of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized a... |
| CVE-2024-55023 | MEDIUM | 5.3 | 0.2% | Mar 3, 2026 | Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 was discovered to contain a hardcoded encryption key which could allow... |
| CVE-2024-43766 | MEDIUM | 6.5 | 0.1% | Mar 2, 2026 | In multiple functions of btm_ble_sec.cc, there is a possible unencrypted communication due to Invalid error handling. Th... |
| CVE-2024-50337 | MEDIUM | 5.3 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to... |
| CVE-2024-10938 | MEDIUM | 6.5 | 0.3% | Feb 27, 2026 | The OVRI Payment plugin for WordPress contains malicious .htaccess files in version 1.7.0. The files contain directives ... |
| CVE-2024-56208 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in desertthemes NewsM... |
| CVE-2024-54222 | MEDIUM | 4.3 | 0.3% | Feb 20, 2026 | Missing Authorization vulnerability in Seraphinite Solutions Seraphinite Accelerator seraphinite-accelerator allows Retr... |
| CVE-2024-52387 | MEDIUM | 5.9 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liton Arefin Maste... |
| CVE-2024-51915 | MEDIUM | 6.5 | 0.2% | Feb 20, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiteSpeed Technolo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now