2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1905 | MEDIUM | 5.9 | 0.5% | Apr 29, 2024 | The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-33649 | MEDIUM | 6.5 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widget... |
| CVE-2024-33648 | MEDIUM | 6.5 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recen... |
| CVE-2024-33643 | MEDIUM | 5.9 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Adv... |
| CVE-2024-33640 | MEDIUM | 6.5 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Googl... |
| CVE-2024-3096 | MEDIUM | 6.5 | 1.5% | Apr 29, 2024 | In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() ... |
| CVE-2024-2756 | MEDIUM | 6.5 | 37.9% | Apr 29, 2024 | Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site at... |
| CVE-2024-4297 | MEDIUM | 4.9 | 0.7% | Apr 29, 2024 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to fil... |
| CVE-2024-4296 | MEDIUM | 4.9 | 0.7% | Apr 29, 2024 | The account management interface of HGiga iSherlock (including MailSherlock, SpamSherlock, AuditSherlock) fails to filte... |
| CVE-2024-33903 | MEDIUM | 5.9 | 0.5% | Apr 29, 2024 | In CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part be... |
| CVE-2024-33883 | MEDIUM | 4 | 0.6% | Apr 28, 2024 | The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection. |
| CVE-2024-4293 | MEDIUM | 5.4 | 0.6% | Apr 27, 2024 | A vulnerability classified as problematic was found in PHPGurukul Doctor Appointment Management System 1.0. Affected by ... |
| CVE-2024-33851 | MEDIUM | 4.3 | 0.4% | Apr 27, 2024 | phpecc, as used in paragonie/phpecc before 2.0.1, has a branch-based timing leak in Point addition. (This is related to ... |
| CVE-2024-4292 | MEDIUM | 6.5 | 0.4% | Apr 27, 2024 | A vulnerability classified as critical has been found in Contemporary Controls BASrouter BACnet BASRT-B 2.7.2. Affected ... |
| CVE-2024-4257 | MEDIUM | 6.5 | 12.1% | Apr 27, 2024 | A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This... |
| CVE-2024-4256 | MEDIUM | 4.8 | 0.5% | Apr 27, 2024 | A vulnerability was found in Techkshetra Info Solutions Savsoft Quiz 6.0 and classified as problematic. Affected by this... |
| CVE-2024-3309 | MEDIUM | 5.4 | 0.3% | Apr 27, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's... |
| CVE-2024-2838 | MEDIUM | 6.4 | 0.3% | Apr 27, 2024 | The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo... |
| CVE-2024-2258 | MEDIUM | 5.4 | 0.4% | Apr 27, 2024 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-31828 | MEDIUM | 6.1 | 0.5% | Apr 26, 2024 | Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensit... |
| CVE-2024-31741 | MEDIUM | 6.1 | 0.4% | Apr 26, 2024 | Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string i... |
| CVE-2024-32887 | MEDIUM | 5.5 | 0.6% | Apr 26, 2024 | Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr... |
| CVE-2024-28326 | MEDIUM | 6.8 | 0.3% | Apr 26, 2024 | Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access ... |
| CVE-2024-28325 | MEDIUM | 6.1 | 0.1% | Apr 26, 2024 | Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access ... |
| CVE-2024-4235 | MEDIUM | 4.9 | 0.6% | Apr 26, 2024 | A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown co... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now