2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4279 | MEDIUM | 6.5 | 0.4% | May 16, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2024-3644 | MEDIUM | 4.8 | 0.4% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-3642 | MEDIUM | 6.9 | 0.3% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow a... |
| CVE-2024-3641 | MEDIUM | 6.1 | 0.4% | May 16, 2024 | The Newsletter Popup WordPress plugin through 1.2 does not sanitise and escape some parameters, which could allow unauth... |
| CVE-2024-4929 | MEDIUM | 4.3 | 0.3% | May 16, 2024 | A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affect... |
| CVE-2024-4984 | MEDIUM | 6.4 | 0.6% | May 16, 2024 | The Yoast SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ author meta in al... |
| CVE-2024-4926 | MEDIUM | 6.5 | 0.5% | May 16, 2024 | A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0. It has been cla... |
| CVE-2024-4925 | MEDIUM | 6.5 | 0.5% | May 16, 2024 | A vulnerability was found in SourceCodester School Intramurals Student Attendance Management System 1.0 and classified a... |
| CVE-2024-4922 | MEDIUM | 6.1 | 0.4% | May 16, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Image Stack Website 1.0. This a... |
| CVE-2024-35184 | MEDIUM | 5.5 | 0.5% | May 15, 2024 | Paperless-ngx is a document management system that transforms physical documents into a searchable online archive. Start... |
| CVE-2024-35183 | MEDIUM | 4.4 | 0.2% | May 15, 2024 | wolfictl is a command line tool for working with Wolfi. A git authentication issue in versions prior to 0.16.10 allows a... |
| CVE-2024-4976 | MEDIUM | 5.5 | 0.2% | May 15, 2024 | Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference. |
| CVE-2024-4950 | MEDIUM | 6.5 | 0.9% | May 15, 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convince... |
| CVE-2024-4949 | MEDIUM | 6.5 | 0.9% | May 15, 2024 | Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-4948 | MEDIUM | 6.5 | 0.9% | May 15, 2024 | Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-4911 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. A... |
| CVE-2024-27243 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via... |
| CVE-2024-4910 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical... |
| CVE-2024-4904 | MEDIUM | 6.3 | 0.6% | May 15, 2024 | A vulnerability was found in Byzoro Smart S200 Management Platform up to 20240507. It has been rated as critical. This i... |
| CVE-2024-34913 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | An arbitrary file upload vulnerability in r-pan-scaffolding v5.0 and below allows attackers to execute arbitrary code vi... |
| CVE-2024-34909 | MEDIUM | 5.4 | 0.5% | May 15, 2024 | An arbitrary file upload vulnerability in KYKMS v1.0.1 and below allows attackers to execute arbitrary code via uploadin... |
| CVE-2024-34906 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | An arbitrary file upload vulnerability in dootask v0.30.13 allows attackers to execute arbitrary code via uploading a cr... |
| CVE-2024-31410 | MEDIUM | 6.5 | 0.2% | May 15, 2024 | The devices which CyberPower PowerPanel manages use identical certificates based on a hard-coded cryptographic key. Thi... |
| CVE-2024-4909 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critic... |
| CVE-2024-4908 | MEDIUM | 6.5 | 0.4% | May 15, 2024 | A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. This ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now