2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33791 | MEDIUM | 4.6 | 0.4% | May 3, 2024 | A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web sc... |
| CVE-2024-30851 | MEDIUM | 6.5 | 4.6% | May 3, 2024 | Directory Traversal vulnerability in codesiddhant Jasmin Ransomware v.1.0.1 allows an attacker to obtain sensitive infor... |
| CVE-2024-34449 | MEDIUM | 6.1 | 0.4% | May 3, 2024 | Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigat... |
| CVE-2024-3109 | MEDIUM | 6.3 | 0.3% | May 3, 2024 | A hard-coded AES key vulnerability was reported in the Motorola GuideMe application, along with a lack of URI sanitatio... |
| CVE-2024-3108 | MEDIUM | 5.5 | 0.2% | May 3, 2024 | An implicit intent vulnerability was reported for Motorola’s Time Weather Widget application that could allow a local a... |
| CVE-2024-1395 | MEDIUM | 6.7 | 0.2% | May 3, 2024 | Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to... |
| CVE-2024-34062 | MEDIUM | 4.8 | 0.4% | May 3, 2024 | tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-s... |
| CVE-2024-33937 | MEDIUM | 4.3 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in Nico Martin Progressive WordPress (PWA).This issue affects Progressive WordPress ... |
| CVE-2024-33931 | MEDIUM | 6.5 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from ... |
| CVE-2024-33929 | MEDIUM | 5.3 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in wpWax Directorist.This issue affects Directorist: from n/a through 7.8.6. |
| CVE-2024-33925 | MEDIUM | 4.3 | 0.3% | May 3, 2024 | Missing Authorization vulnerability in Adrian Mörchen Embed Google Fonts.This issue affects Embed Google Fonts: from n/a... |
| CVE-2024-33923 | MEDIUM | 6.3 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Documen... |
| CVE-2024-33920 | MEDIUM | 5.3 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in Kama Democracy Poll.This issue affects Democracy Poll: from n/a through 6.0.3. |
| CVE-2024-33919 | MEDIUM | 6.5 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in Rometheme RomethemeKit For Elementor.This issue affects RomethemeKit For Elemento... |
| CVE-2024-33915 | MEDIUM | 4.3 | 0.3% | May 3, 2024 | Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3... |
| CVE-2024-23914 | MEDIUM | 5.7 | 0.3% | May 3, 2024 | Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Associat... |
| CVE-2024-23913 | MEDIUM | 4 | 0.2% | May 3, 2024 | Use of Out-of-range Pointer Offset vulnerability in Merge DICOM Toolkit C/C++ on Windows. When deprecated MC_XML_To_Mes... |
| CVE-2024-23912 | MEDIUM | 4 | 0.2% | May 3, 2024 | Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read ... |
| CVE-2024-33941 | MEDIUM | 5.3 | 0.4% | May 3, 2024 | Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama... |
| CVE-2024-33927 | MEDIUM | 6.5 | 0.3% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Team GIPHY Giphypr... |
| CVE-2024-33926 | MEDIUM | 6.5 | 0.3% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Karl Kiesinger GWP... |
| CVE-2024-33918 | MEDIUM | 5.9 | 0.4% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maxim K AJAX Login... |
| CVE-2024-33916 | MEDIUM | 6.5 | 0.3% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Co... |
| CVE-2024-32831 | MEDIUM | 5.9 | 0.3% | May 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lorna Timbah (webg... |
| CVE-2024-28072 | MEDIUM | 4.9 | 0.6% | May 3, 2024 | A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now