2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34374 | MEDIUM | 5.4 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuomodoSoft Elemen... |
| CVE-2024-34373 | MEDIUM | 5.4 | 0.3% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus ... |
| CVE-2024-34372 | MEDIUM | 5.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a throug... |
| CVE-2024-34371 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects L... |
| CVE-2024-34368 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mooberry Dreams Mooberry Book Manager.This i... |
| CVE-2024-34366 | MEDIUM | 5.9 | 0.4% | May 6, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Downloa... |
| CVE-2024-33910 | MEDIUM | 5.3 | 0.4% | May 6, 2024 | Missing Authorization vulnerability in Supsystic Digital Publications by Supsystic.This issue affects Digital Publicatio... |
| CVE-2024-34383 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in The SEO Guys at SEOPress SEOPress.This issue affects S... |
| CVE-2024-34382 | MEDIUM | 5.3 | 0.5% | May 6, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in RoboSoft Robo Gallery.This issue affects Rob... |
| CVE-2024-33407 | MEDIUM | 5.9 | 0.3% | May 6, 2024 | SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 all... |
| CVE-2024-34471 | MEDIUM | 5.4 | 0.7% | May 6, 2024 | An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exist... |
| CVE-2024-34250 | MEDIUM | 6.2 | 0.3% | May 6, 2024 | A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote... |
| CVE-2024-34093 | MEDIUM | 5.3 | 0.4% | May 6, 2024 | An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An... |
| CVE-2024-34091 | MEDIUM | 5.4 | 0.5% | May 6, 2024 | An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability.... |
| CVE-2024-34090 | MEDIUM | 5.4 | 0.4% | May 6, 2024 | An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability.... |
| CVE-2024-34089 | MEDIUM | 5.4 | 0.5% | May 6, 2024 | An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability.... |
| CVE-2024-26312 | MEDIUM | 4.3 | 0.4% | May 6, 2024 | Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker co... |
| CVE-2024-34472 | MEDIUM | 5.5 | 0.7% | May 6, 2024 | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerabili... |
| CVE-2024-34078 | MEDIUM | 6.1 | 0.6% | May 6, 2024 | html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), ... |
| CVE-2024-34064 | MEDIUM | 5.4 | 1.0% | May 6, 2024 | Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non... |
| CVE-2024-33113 | MEDIUM | 5.3 | 3.4% | May 6, 2024 | D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php. |
| CVE-2024-33111 | MEDIUM | 5.4 | 0.8% | May 6, 2024 | D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php. |
| CVE-2024-33752 | MEDIUM | 6.3 | 4.6% | May 6, 2024 | An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be e... |
| CVE-2024-33829 | MEDIUM | 5.4 | 0.2% | May 6, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=up... |
| CVE-2024-4528 | MEDIUM | 4.8 | 0.6% | May 6, 2024 | A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as problematic. Affected ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now