2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4513 | MEDIUM | 6.1 | 0.6% | May 6, 2024 | A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management S... |
| CVE-2024-4512 | MEDIUM | 5.4 | 0.6% | May 6, 2024 | A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability a... |
| CVE-2024-4511 | MEDIUM | 6.3 | 0.6% | May 6, 2024 | A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. Th... |
| CVE-2024-34529 | MEDIUM | 4.8 | 0.4% | May 6, 2024 | Nebari through 2024.4.1 prints the temporary Keycloak root password. |
| CVE-2024-34525 | MEDIUM | 5.3 | 0.2% | May 6, 2024 | FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file. |
| CVE-2024-34519 | MEDIUM | 6.8 | 0.4% | May 5, 2024 | Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a use... |
| CVE-2024-34509 | MEDIUM | 5.3 | 0.7% | May 5, 2024 | dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message. |
| CVE-2024-34508 | MEDIUM | 4.3 | 0.7% | May 5, 2024 | dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message. |
| CVE-2024-34500 | MEDIUM | 6.1 | 0.5% | May 5, 2024 | An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x b... |
| CVE-2024-34490 | MEDIUM | 5.1 | 0.2% | May 5, 2024 | In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the cont... |
| CVE-2024-34484 | MEDIUM | 5.3 | 0.5% | May 5, 2024 | OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.l... |
| CVE-2024-34476 | MEDIUM | 5.3 | 0.5% | May 5, 2024 | Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_... |
| CVE-2024-34473 | MEDIUM | 5.3 | 0.4% | May 4, 2024 | An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message t... |
| CVE-2024-34468 | MEDIUM | 6.1 | 0.3% | May 4, 2024 | Rukovoditel before 3.5.3 allows XSS via user_photo to My Page. |
| CVE-2024-34467 | MEDIUM | 6.1 | 0.4% | May 4, 2024 | ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_e... |
| CVE-2024-34462 | MEDIUM | 6.1 | 0.3% | May 4, 2024 | Alinto SOGo through 5.10.0 allows XSS during attachment preview. |
| CVE-2024-1050 | MEDIUM | 4.3 | 0.4% | May 4, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2024-34460 | MEDIUM | 6.5 | 0.6% | May 4, 2024 | The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5... |
| CVE-2024-3237 | MEDIUM | 5.4 | 0.4% | May 4, 2024 | The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2024-3868 | MEDIUM | 5.4 | 0.4% | May 4, 2024 | The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name ... |
| CVE-2024-34453 | MEDIUM | 4.3 | 0.3% | May 3, 2024 | TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity... |
| CVE-2024-34075 | MEDIUM | 6.2 | 0.3% | May 3, 2024 | kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the ... |
| CVE-2024-34068 | MEDIUM | 6.4 | 0.4% | May 3, 2024 | Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game serv... |
| CVE-2024-34067 | MEDIUM | 6.1 | 0.5% | May 3, 2024 | Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg... |
| CVE-2024-33793 | MEDIUM | 5.3 | 0.3% | May 3, 2024 | netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now