2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32051 | MEDIUM | 6.5 | 0.3% | Apr 24, 2024 | Insertion of sensitive information into log file issue exists in RoamWiFi R10 prior to 4.8.45. If this vulnerability is ... |
| CVE-2024-3261 | MEDIUM | 4.8 | 0.4% | Apr 24, 2024 | The Strong Testimonials WordPress plugin before 3.1.12 does not validate and escape some of its Testimonial fields befor... |
| CVE-2024-2404 | MEDIUM | 5.4 | 0.4% | Apr 24, 2024 | The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow l... |
| CVE-2024-2402 | MEDIUM | 5.4 | 0.4% | Apr 24, 2024 | The Better Comments WordPress plugin before 1.5.6 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-1756 | MEDIUM | 6.5 | 0.3% | Apr 24, 2024 | The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, a... |
| CVE-2024-1743 | MEDIUM | 5.9 | 0.3% | Apr 24, 2024 | The WooCommerce Customers Manager WordPress plugin before 29.8 does not sanitise and escape various parameters before ou... |
| CVE-2024-4075 | MEDIUM | 6.1 | 0.6% | Apr 23, 2024 | A vulnerability classified as problematic has been found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. T... |
| CVE-2024-4074 | MEDIUM | 6.1 | 0.6% | Apr 23, 2024 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been rated as problematic... |
| CVE-2024-4073 | MEDIUM | 5.4 | 0.5% | Apr 23, 2024 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been declared as problema... |
| CVE-2024-4072 | MEDIUM | 5.4 | 0.5% | Apr 23, 2024 | A vulnerability was found in Kashipara Online Furniture Shopping Ecommerce Website 1.0. It has been classified as proble... |
| CVE-2024-30886 | MEDIUM | 5.4 | 0.3% | Apr 23, 2024 | A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execut... |
| CVE-2024-32875 | MEDIUM | 6.1 | 0.5% | Apr 23, 2024 | Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown f... |
| CVE-2024-32869 | MEDIUM | 5.3 | 0.6% | Apr 23, 2024 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using... |
| CVE-2024-31208 | MEDIUM | 6.5 | 1.5% | Apr 23, 2024 | Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse ins... |
| CVE-2024-21979 | MEDIUM | 5.3 | 0.2% | Apr 23, 2024 | An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with a... |
| CVE-2024-21972 | MEDIUM | 5.3 | 0.2% | Apr 23, 2024 | An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with a... |
| CVE-2024-33213 | MEDIUM | 6.5 | 0.4% | Apr 23, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterfac... |
| CVE-2024-32679 | MEDIUM | 5.3 | 0.4% | Apr 23, 2024 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a... |
| CVE-2024-31804 | MEDIUM | 6.7 | 0.7% | Apr 23, 2024 | An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privile... |
| CVE-2024-2477 | MEDIUM | 5.4 | 0.3% | Apr 23, 2024 | The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an up... |
| CVE-2024-3911 | MEDIUM | 6.5 | 0.5% | Apr 23, 2024 | An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of r... |
| CVE-2024-30800 | MEDIUM | 5.6 | 0.2% | Apr 23, 2024 | PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the ... |
| CVE-2024-26922 | MEDIUM | 5.5 | 0.3% | Apr 23, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o... |
| CVE-2024-3491 | MEDIUM | 6.4 | 0.3% | Apr 23, 2024 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2024-3732 | MEDIUM | 5.4 | 0.3% | Apr 23, 2024 | The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to St... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now