2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4376 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fanc... |
| CVE-2024-4205 | MEDIUM | 4.3 | 0.3% | May 31, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa... |
| CVE-2024-23847 | MEDIUM | 5.9 | 0.2% | May 31, 2024 | Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co... |
| CVE-2024-5418 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribu... |
| CVE-2024-1298 | MEDIUM | 6 | 0.2% | May 30, 2024 | EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 ... |
| CVE-2024-35189 | MEDIUM | 6.5 | 0.6% | May 30, 2024 | Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `Conne... |
| CVE-2024-32877 | MEDIUM | 4.7 | 0.3% | May 30, 2024 | Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a... |
| CVE-2024-35228 | MEDIUM | 5.5 | 0.3% | May 30, 2024 | Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in th... |
| CVE-2024-35468 | MEDIUM | 5.4 | 0.4% | May 30, 2024 | A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers ... |
| CVE-2024-36118 | MEDIUM | 4.3 | 0.3% | May 30, 2024 | MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions ca... |
| CVE-2024-35429 | MEDIUM | 6.5 | 0.9% | May 30, 2024 | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord. |
| CVE-2024-35352 | MEDIUM | 6.1 | 0.3% | May 30, 2024 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentifie... |
| CVE-2024-35351 | MEDIUM | 5.4 | 0.3% | May 30, 2024 | A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentifie... |
| CVE-2024-36959 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_d... |
| CVE-2024-36958 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure tha... |
| CVE-2024-36957 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace ... |
| CVE-2024-36956 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Free all thermal zone debug memory... |
| CVE-2024-36954 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __... |
| CVE-2024-36953 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgi... |
| CVE-2024-36952 | MEDIUM | 4.7 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to... |
| CVE-2024-36951 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: range check cp bad op exception interru... |
| CVE-2024-36950 | MEDIUM | 4.4 | 0.3% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset interrupts between I... |
| CVE-2024-36949 | MEDIUM | 4.7 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: sync all devices to wait all processes ... |
| CVE-2024-36948 | MEDIUM | 5.5 | 0.2% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_migrate: Cast to output precision before ... |
| CVE-2024-36947 | MEDIUM | 5.5 | 0.5% | May 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now