2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5410 | MEDIUM | 5.4 | 13.2% | May 28, 2024 | Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects ... |
| CVE-2024-28880 | MEDIUM | 6.5 | 0.6% | May 28, 2024 | Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the prod... |
| CVE-2024-34923 | MEDIUM | 6.1 | 0.3% | May 27, 2024 | In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before... |
| CVE-2024-36105 | MEDIUM | 5.3 | 0.7% | May 27, 2024 | dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ... |
| CVE-2024-36037 | MEDIUM | 5.5 | 0.5% | May 27, 2024 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session... |
| CVE-2024-36036 | MEDIUM | 4.2 | 0.4% | May 27, 2024 | Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive... |
| CVE-2024-35238 | MEDIUM | 5.3 | 0.5% | May 27, 2024 | Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerab... |
| CVE-2024-27310 | MEDIUM | 6.5 | 2.3% | May 27, 2024 | Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP inpu... |
| CVE-2024-35236 | MEDIUM | 4.8 | 0.8% | May 27, 2024 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious s... |
| CVE-2024-35229 | MEDIUM | 5.3 | 0.4% | May 27, 2024 | ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a ve... |
| CVE-2024-32978 | MEDIUM | 6.6 | 0.6% | May 27, 2024 | Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecu... |
| CVE-2024-5409 | MEDIUM | 6.1 | 0.3% | May 27, 2024 | RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker coul... |
| CVE-2024-5408 | MEDIUM | 6.1 | 0.3% | May 27, 2024 | Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnera... |
| CVE-2024-5406 | MEDIUM | 6.3 | 0.3% | May 27, 2024 | A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text an... |
| CVE-2024-5405 | MEDIUM | 6.3 | 0.3% | May 27, 2024 | A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash... |
| CVE-2024-36383 | MEDIUM | 5.3 | 0.4% | May 27, 2024 | An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the st... |
| CVE-2024-4534 | MEDIUM | 6.1 | 0.2% | May 27, 2024 | The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing saniti... |
| CVE-2024-4533 | MEDIUM | 6.5 | 0.5% | May 27, 2024 | The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a ... |
| CVE-2024-4532 | MEDIUM | 6.4 | 0.3% | May 27, 2024 | The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-4530 | MEDIUM | 6.3 | 0.2% | May 27, 2024 | The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-4529 | MEDIUM | 5 | 0.2% | May 27, 2024 | The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers t... |
| CVE-2024-3939 | MEDIUM | 5.4 | 0.4% | May 27, 2024 | The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high priv... |
| CVE-2024-35297 | MEDIUM | 4.7 | 0.4% | May 27, 2024 | Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an ... |
| CVE-2024-35291 | MEDIUM | 6.1 | 0.3% | May 27, 2024 | Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is e... |
| CVE-2024-36384 | MEDIUM | 6.1 | 0.3% | May 27, 2024 | Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now