2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26306 | MEDIUM | 5.9 | 1.1% | May 14, 2024 | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channe... |
| CVE-2024-25662 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Cross-Site Scripting ... |
| CVE-2024-24157 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site... |
| CVE-2024-23236 | MEDIUM | 5.5 | 0.3% | May 14, 2024 | A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to ... |
| CVE-2024-23229 | MEDIUM | 5.5 | 0.3% | May 14, 2024 | This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5,... |
| CVE-2024-22910 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | Cross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code ... |
| CVE-2024-22344 | MEDIUM | 6.1 | 0.5% | May 14, 2024 | IBM TXSeries for Multiplatforms 8.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code,... |
| CVE-2024-22064 | MEDIUM | 6.5 | 0.5% | May 14, 2024 | ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set... |
| CVE-2024-1693 | MEDIUM | 4.3 | 0.4% | May 14, 2024 | The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-1467 | MEDIUM | 4.3 | 0.6% | May 14, 2024 | The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Sid... |
| CVE-2024-1230 | MEDIUM | 4.3 | 0.6% | May 14, 2024 | The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2024-1229 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capabil... |
| CVE-2024-1166 | MEDIUM | 6.4 | 0.3% | May 14, 2024 | The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-0445 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ele... |
| CVE-2024-0098 | MEDIUM | 5.5 | 0.2% | May 14, 2024 | NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text t... |
| CVE-2024-33382 | MEDIUM | 5.3 | 0.5% | May 8, 2024 | An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration |
| CVE-2024-25528 | MEDIUM | 5.9 | 0.3% | May 8, 2024 | RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffai... |
| CVE-2024-28971 | MEDIUM | 4.9 | 0.3% | May 8, 2024 | Dell Update Manager Plugin, versions 1.4.0 through 1.5.0, contains a Plain-text Password Storage Vulnerability in Log fi... |
| CVE-2024-24908 | MEDIUM | 6.5 | 0.6% | May 8, 2024 | Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A... |
| CVE-2024-24788 | MEDIUM | 5.9 | 1.0% | May 8, 2024 | A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop. |
| CVE-2024-24787 | MEDIUM | 6.4 | 0.8% | May 8, 2024 | On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ... |
| CVE-2024-33612 | MEDIUM | 6.8 | 0.2% | May 8, 2024 | An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impe... |
| CVE-2024-33604 | MEDIUM | 6.1 | 0.3% | May 8, 2024 | A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that... |
| CVE-2024-32761 | MEDIUM | 6.5 | 0.5% | May 8, 2024 | Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running ... |
| CVE-2024-28889 | MEDIUM | 5.9 | 0.4% | May 8, 2024 | When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now