2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3477 | MEDIUM | 4.3 | 0.3% | May 2, 2024 | The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers... |
| CVE-2024-3472 | MEDIUM | 5.9 | 0.2% | May 2, 2024 | The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which coul... |
| CVE-2024-2405 | MEDIUM | 4.5 | 0.3% | May 2, 2024 | The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers ... |
| CVE-2024-33307 | MEDIUM | 5.4 | 0.4% | May 1, 2024 | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in... |
| CVE-2024-25676 | MEDIUM | 4.7 | 0.3% | May 1, 2024 | An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanit... |
| CVE-2024-33431 | MEDIUM | 6.5 | 0.9% | May 1, 2024 | An issue in phiola/src/afilter/conv.c:115 of phiola v2.0-rc22 allows a remote attacker to cause a denial of service via ... |
| CVE-2024-33424 | MEDIUM | 6.1 | 0.4% | May 1, 2024 | A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary ... |
| CVE-2024-33393 | MEDIUM | 6.2 | 0.2% | May 1, 2024 | An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted c... |
| CVE-2024-33304 | MEDIUM | 6.1 | 0.4% | May 1, 2024 | SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users. |
| CVE-2024-22830 | MEDIUM | 5.3 | 0.2% | May 1, 2024 | Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control wh... |
| CVE-2024-33442 | MEDIUM | 4.3 | 0.6% | May 1, 2024 | An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component. |
| CVE-2024-32213 | MEDIUM | 5.3 | 0.9% | May 1, 2024 | The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, ... |
| CVE-2024-32211 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive informa... |
| CVE-2024-32210 | MEDIUM | 5.3 | 0.4% | May 1, 2024 | The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default ... |
| CVE-2024-30176 | MEDIUM | 5.3 | 0.4% | May 1, 2024 | In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared w... |
| CVE-2024-33518 | MEDIUM | 5.3 | 0.5% | May 1, 2024 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the ... |
| CVE-2024-33513 | MEDIUM | 5.9 | 0.5% | May 1, 2024 | Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protoco... |
| CVE-2024-20357 | MEDIUM | 5.9 | 0.5% | May 1, 2024 | A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiat... |
| CVE-2024-24912 | MEDIUM | 6.7 | 0.2% | May 1, 2024 | A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions ... |
| CVE-2024-4060 | MEDIUM | 6.5 | 1.0% | May 1, 2024 | Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-4059 | MEDIUM | 6.5 | 0.9% | May 1, 2024 | Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data v... |
| CVE-2024-31413 | MEDIUM | 5.9 | 0.2% | May 1, 2024 | Free of pointer not at start of buffer vulnerability exists in CX-One CX-One CXONE-AL[][]D-V4 (The version which was ins... |
| CVE-2024-28775 | MEDIUM | 5.4 | 0.4% | May 1, 2024 | IBM WebSphere Automation 1.7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2024-27391 | MEDIUM | 5.5 | 0.3% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: do not realloc workqueue everytime ... |
| CVE-2024-27390 | MEDIUM | 5.5 | 0.2% | May 1, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: remove one synchronize_net() barrier i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now