2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2159 | MEDIUM | 4.7 | 0.5% | Apr 26, 2024 | The Social Sharing Plugin WordPress plugin before 3.3.61 does not validate and escape some of its shortcode attributes ... |
| CVE-2024-0905 | MEDIUM | 6.3 | 0.5% | Apr 26, 2024 | The Fancy Product Designer WordPress plugin before 6.1.8 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-32404 | MEDIUM | 6 | 0.8% | Apr 26, 2024 | Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execut... |
| CVE-2024-33670 | MEDIUM | 4.3 | 0.5% | Apr 26, 2024 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a u... |
| CVE-2024-33669 | MEDIUM | 6.8 | 0.6% | Apr 26, 2024 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned whil... |
| CVE-2024-33667 | MEDIUM | 6.5 | 0.6% | Apr 26, 2024 | An issue was discovered in Zammad before 6.3.0. An authenticated agent could perform a remote Denial of Service attack b... |
| CVE-2024-33665 | MEDIUM | 6.1 | 0.5% | Apr 26, 2024 | angular-translate through 2.19.1 allows XSS via a crafted key that is used by the translate directive. NOTE: the vendor ... |
| CVE-2024-33664 | MEDIUM | 5.3 | 0.8% | Apr 26, 2024 | python-jose through 3.3.0 allows attackers to cause a denial of service (resource consumption) during a decode via a cra... |
| CVE-2024-33663 | MEDIUM | 6.5 | 0.3% | Apr 26, 2024 | python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-... |
| CVE-2024-3265 | MEDIUM | 4.7 | 0.4% | Apr 25, 2024 | The Advanced Search WordPress plugin through 1.1.6 does not properly escape parameters appended to an SQL query, making ... |
| CVE-2024-31610 | MEDIUM | 6.3 | 0.4% | Apr 25, 2024 | File Upload vulnerability in the function for employees to upload avatars in Code-Projects Simple School Management Syst... |
| CVE-2024-30939 | MEDIUM | 6.8 | 0.4% | Apr 25, 2024 | An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attac... |
| CVE-2024-3623 | MEDIUM | 6.5 | 0.4% | Apr 25, 2024 | A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in p... |
| CVE-2024-3508 | MEDIUM | 4.3 | 0.5% | Apr 25, 2024 | A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endp... |
| CVE-2024-32649 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s... |
| CVE-2024-32648 | MEDIUM | 5.3 | 0.4% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Prior to version 0.3.0, default functions ... |
| CVE-2024-32647 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `c... |
| CVE-2024-32646 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `s... |
| CVE-2024-32645 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, incorrect va... |
| CVE-2024-2905 | MEDIUM | 6.2 | 0.3% | Apr 25, 2024 | A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds hav... |
| CVE-2024-32481 | MEDIUM | 5.3 | 0.8% | Apr 25, 2024 | Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to ver... |
| CVE-2024-32467 | MEDIUM | 6.5 | 0.5% | Apr 25, 2024 | MeterSphere is an open source continuous testing platform. Prior to version 2.10.14-lts, members without space permissio... |
| CVE-2024-31574 | MEDIUM | 5 | 0.3% | Apr 25, 2024 | Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script |
| CVE-2024-30890 | MEDIUM | 4.7 | 0.4% | Apr 25, 2024 | Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categori... |
| CVE-2024-2467 | MEDIUM | 5.9 | 0.5% | Apr 25, 2024 | A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plai... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now