2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34422 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in trinhtuantai Viet ... |
| CVE-2024-34421 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpsurface BlogLent... |
| CVE-2024-34420 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in talspotim Comments... |
| CVE-2024-34419 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nathan Vonnahme Co... |
| CVE-2024-34418 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tech9logy Creators... |
| CVE-2024-34417 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Toidicode.Com (tha... |
| CVE-2024-34415 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Thim Ele... |
| CVE-2024-34354 | MEDIUM | 6.5 | 0.3% | May 14, 2024 | CMSaaSStarter is a SaaS template/boilerplate built with SvelteKit, Tailwind, and Supabase. Any forks of the CMSaaSStarte... |
| CVE-2024-34353 | MEDIUM | 5.5 | 0.2% | May 14, 2024 | The matrix-sdk-crypto crate, part of the Matrix Rust SDK project, is an implementation of a Matrix end-to-end encryption... |
| CVE-2024-34349 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript c... |
| CVE-2024-34245 | MEDIUM | 6.5 | 0.8% | May 14, 2024 | An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by speci... |
| CVE-2024-34230 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execu... |
| CVE-2024-34225 | MEDIUM | 6.1 | 0.6% | May 14, 2024 | Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP... |
| CVE-2024-34223 | MEDIUM | 4.3 | 0.5% | May 14, 2024 | Insecure permission vulnerability in /hrm/leaverequest.php in SourceCodester Human Resource Management System 1.0 allow ... |
| CVE-2024-34222 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter. |
| CVE-2024-34206 | MEDIUM | 6.5 | 1.3% | May 14, 2024 | TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the set... |
| CVE-2024-34202 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setMacFilte... |
| CVE-2024-34081 | MEDIUM | 4.8 | 0.6% | May 14, 2024 | MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an att... |
| CVE-2024-34080 | MEDIUM | 5.3 | 0.7% | May 14, 2024 | MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another iss... |
| CVE-2024-34074 | MEDIUM | 6.1 | 0.6% | May 14, 2024 | Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument... |
| CVE-2024-33956 | MEDIUM | 4.3 | 0.4% | May 14, 2024 | Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom... |
| CVE-2024-33955 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Free... |
| CVE-2024-33954 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Plis... |
| CVE-2024-33953 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adv... |
| CVE-2024-33952 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Uni... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now