2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23772 | MEDIUM | 6.6 | 0.3% | Apr 30, 2024 | An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability ex... |
| CVE-2024-22405 | MEDIUM | 5.5 | 0.2% | Apr 30, 2024 | XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted... |
| CVE-2024-3072 | MEDIUM | 4.3 | 0.3% | Apr 30, 2024 | The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-1371 | MEDIUM | 6.5 | 0.6% | Apr 30, 2024 | The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capabi... |
| CVE-2024-0216 | MEDIUM | 6.4 | 0.3% | Apr 30, 2024 | The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in v... |
| CVE-2024-34047 | MEDIUM | 4.3 | 0.3% | Apr 30, 2024 | O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler. |
| CVE-2024-34044 | MEDIUM | 5.3 | 0.5% | Apr 30, 2024 | The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL. |
| CVE-2024-34043 | MEDIUM | 5.3 | 0.2% | Apr 30, 2024 | O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message. |
| CVE-2024-33522 | MEDIUM | 6.7 | 0.2% | Apr 29, 2024 | In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Cal... |
| CVE-2024-33401 | MEDIUM | 4.4 | 0.2% | Apr 29, 2024 | Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum para... |
| CVE-2024-28294 | MEDIUM | 6.5 | 0.6% | Apr 29, 2024 | Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter. |
| CVE-2024-33272 | MEDIUM | 6.8 | 0.4% | Apr 29, 2024 | SQL injection vulnerability in KnowBand for PrestaShop autosuggest before 2.0.0 allows an attacker to run arbitrary SQL ... |
| CVE-2024-33345 | MEDIUM | 6.5 | 0.8% | Apr 29, 2024 | D-Link DIR-823G A1V1.0.2B05 was found to contain a Null-pointer dereference in the main function of upload_firmware.cgi,... |
| CVE-2024-34020 | MEDIUM | 6.5 | 0.6% | Apr 29, 2024 | A stack-based buffer overflow was found in the putSDN() function of mail.c in hcode through 2.1. |
| CVE-2024-34011 | MEDIUM | 6.8 | 0.2% | Apr 29, 2024 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec... |
| CVE-2024-23995 | MEDIUM | 6.1 | 1.0% | Apr 29, 2024 | Cross Site Scripting (XSS) in Beekeeper Studio 4.1.13 and earlier allows remote attackers to execute arbitrary code in t... |
| CVE-2024-4310 | MEDIUM | 5.4 | 0.3% | Apr 29, 2024 | Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to se... |
| CVE-2024-33588 | MEDIUM | 5.4 | 0.4% | Apr 29, 2024 | Missing Authorization vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.This issue affe... |
| CVE-2024-33587 | MEDIUM | 5.3 | 0.4% | Apr 29, 2024 | Missing Authorization vulnerability in Copy Content Protection Team Secure Copy Content Protection and Content Locking.T... |
| CVE-2024-33586 | MEDIUM | 5.3 | 0.4% | Apr 29, 2024 | Missing Authorization vulnerability in Photo Gallery Team Photo Gallery by 10Web.This issue affects Photo Gallery by 10W... |
| CVE-2024-33585 | MEDIUM | 4.3 | 0.3% | Apr 29, 2024 | Missing Authorization vulnerability in Tyche Softwares Payment Gateway Based Fees and Discounts for WooCommerce.This iss... |
| CVE-2024-4304 | MEDIUM | 5.4 | 0.3% | Apr 29, 2024 | A Cross-Site Scripting XSS vulnerability has been detected on GT3 Soluciones SWAL. This vulnerability consists in a ref... |
| CVE-2024-33590 | MEDIUM | 5 | 0.4% | Apr 29, 2024 | Server-Side Request Forgery (SSRF) vulnerability in codeSavory Knowledge Base documentation & wiki plugin – BasePress.Th... |
| CVE-2024-33589 | MEDIUM | 6.5 | 0.5% | Apr 29, 2024 | Missing Authorization vulnerability in WPOmnia KB Support.This issue affects KB Support: from n/a through 1.6.0. |
| CVE-2024-33593 | MEDIUM | 4.3 | 0.3% | Apr 29, 2024 | Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now