2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29660 | MEDIUM | 5.3 | 0.2% | Apr 25, 2024 | Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payl... |
| CVE-2024-25624 | MEDIUM | 6.8 | 0.9% | Apr 25, 2024 | Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations.... |
| CVE-2024-1726 | MEDIUM | 5.3 | 0.7% | Apr 25, 2024 | A flaw was discovered in the RESTEasy Reactive implementation in Quarkus. Due to security checks for some JAX-RS endpoin... |
| CVE-2024-1102 | MEDIUM | 6.5 | 0.8% | Apr 25, 2024 | A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as ... |
| CVE-2024-0874 | MEDIUM | 5.3 | 0.8% | Apr 25, 2024 | A flaw was found in coredns. This issue could lead to invalid cache entries returning due to incorrectly implemented cac... |
| CVE-2024-33592 | MEDIUM | 5.4 | 0.3% | Apr 25, 2024 | Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a throu... |
| CVE-2024-25569 | MEDIUM | 6.5 | 1.1% | Apr 25, 2024 | An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DIC... |
| CVE-2024-4172 | MEDIUM | 4.3 | 0.4% | Apr 25, 2024 | A vulnerability classified as problematic was found in idcCMS 1.35. Affected by this vulnerability is an unknown functio... |
| CVE-2024-4006 | MEDIUM | 4.3 | 0.5% | Apr 25, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions start... |
| CVE-2024-4175 | MEDIUM | 5.4 | 0.3% | Apr 25, 2024 | Unicode transformation vulnerability in Hyperion affecting version 2.0.15. This vulnerability could allow an attacker to... |
| CVE-2024-4174 | MEDIUM | 5.4 | 0.3% | Apr 25, 2024 | Cross-Site Scripting (XSS) vulnerability in Hyperion Web Server affecting version 2.0.15. This vulnerability could allow... |
| CVE-2024-3730 | MEDIUM | 5.4 | 0.3% | Apr 25, 2024 | The Simple Membership plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'swpm_paypal_su... |
| CVE-2024-32676 | MEDIUM | 5.3 | 0.4% | Apr 25, 2024 | Improper Restriction of Excessive Authentication Attempts vulnerability in LoginPress LoginPress Pro allows Removing Imp... |
| CVE-2024-1347 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 befo... |
| CVE-2024-4035 | MEDIUM | 6.4 | 0.3% | Apr 25, 2024 | The Photo Gallery – GT3 Image Gallery & Gutenberg Block Gallery plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2024-3994 | MEDIUM | 5.4 | 0.4% | Apr 25, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-32961 | MEDIUM | 5.4 | 0.3% | Apr 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq B... |
| CVE-2024-3733 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-3988 | MEDIUM | 5.4 | 0.4% | Apr 25, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-3929 | MEDIUM | 6.4 | 0.4% | Apr 25, 2024 | The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for... |
| CVE-2024-3893 | MEDIUM | 4.3 | 0.4% | Apr 25, 2024 | The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized l... |
| CVE-2024-4159 | MEDIUM | 5.3 | 0.5% | Apr 25, 2024 | Brocade SANnav before v2.3.0a lacks protection mechanisms on port 2377/TCP and 7946/TCP, which could allow an unauthent... |
| CVE-2024-2907 | MEDIUM | 6.8 | 0.5% | Apr 25, 2024 | The AGCA WordPress plugin before 7.2.2 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2024-26926 | MEDIUM | 5.5 | 0.4% | Apr 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: binder: check offset alignment in binder_get_object... |
| CVE-2024-26925 | MEDIUM | 5.5 | 0.3% | Apr 25, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: release mutex after nft_gc_se... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now