2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20861 | MEDIUM | 6.7 | 0.2% | May 7, 2024 | Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause me... |
| CVE-2024-20859 | MEDIUM | 5.5 | 0.2% | May 7, 2024 | Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pi... |
| CVE-2024-20858 | MEDIUM | 5.5 | 0.2% | May 7, 2024 | Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 ... |
| CVE-2024-20857 | MEDIUM | 5.5 | 0.2% | May 7, 2024 | Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows loc... |
| CVE-2024-20856 | MEDIUM | 4.3 | 0.3% | May 7, 2024 | Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to acce... |
| CVE-2024-20821 | MEDIUM | 4.4 | 0.2% | May 7, 2024 | A vulnerability possible to reconfigure OTP allows local attackers to transit RMA(Return Merchandise Authorization) mode... |
| CVE-2024-2913 | MEDIUM | 6.5 | 0.3% | May 7, 2024 | A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite ... |
| CVE-2024-34413 | MEDIUM | 5.9 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SliceWP allows Sto... |
| CVE-2024-1695 | MEDIUM | 5.7 | 0.2% | May 6, 2024 | A potential security vulnerability has been identified in the HP Application Enabling Software Driver for certain HP PC ... |
| CVE-2024-4568 | MEDIUM | 5.5 | 0.2% | May 6, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow. |
| CVE-2024-33908 | MEDIUM | 5.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Themesgrove WidgetKit.This issue affects WidgetKit: from n/a through 2.5.0. |
| CVE-2024-33907 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | Missing Authorization vulnerability in Michael Nelson Print My Blog print-my-blog.This issue affects Print My Blog: from... |
| CVE-2024-33600 | MEDIUM | 5.9 | 1.2% | May 6, 2024 | nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-f... |
| CVE-2024-33576 | MEDIUM | 6.5 | 0.5% | May 6, 2024 | Missing Authorization vulnerability in Ollybach WPPizza.This issue affects WPPizza: from n/a through 3.18.10. |
| CVE-2024-33121 | MEDIUM | 6.3 | 0.3% | May 6, 2024 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. |
| CVE-2024-33117 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.z... |
| CVE-2024-34390 | MEDIUM | 6.5 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AddonMaster Post G... |
| CVE-2024-34389 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.... |
| CVE-2024-34387 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.... |
| CVE-2024-34381 | MEDIUM | 5.4 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allow... |
| CVE-2024-34380 | MEDIUM | 6.5 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conve... |
| CVE-2024-34379 | MEDIUM | 4.3 | 0.2% | May 6, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Restaurant and Cafe.This issue affects Restaurant and Cafe... |
| CVE-2024-34377 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in A WP Life Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery.This issue... |
| CVE-2024-34376 | MEDIUM | 6.5 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Edge... |
| CVE-2024-34375 | MEDIUM | 5.9 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL Sheets To W... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now