2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3665 | MEDIUM | 5.4 | 0.5% | Apr 23, 2024 | The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's H... |
| CVE-2024-3185 | MEDIUM | 6.8 | 0.2% | Apr 23, 2024 | A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in th... |
| CVE-2024-0900 | MEDIUM | 4.3 | 0.4% | Apr 23, 2024 | The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding... |
| CVE-2024-3664 | MEDIUM | 4.3 | 0.3% | Apr 23, 2024 | The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2024-4031 | MEDIUM | 4.4 | 0.2% | Apr 23, 2024 | Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code. |
| CVE-2024-3889 | MEDIUM | 6.4 | 0.3% | Apr 23, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-2799 | MEDIUM | 6.4 | 0.4% | Apr 23, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image... |
| CVE-2024-2798 | MEDIUM | 6.4 | 0.3% | Apr 23, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-31857 | MEDIUM | 5.4 | 0.6% | Apr 23, 2024 | Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote a... |
| CVE-2024-28890 | MEDIUM | 5.3 | 0.7% | Apr 23, 2024 | Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerabil... |
| CVE-2024-2760 | MEDIUM | 5.5 | 0.2% | Apr 23, 2024 | Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IO... |
| CVE-2024-1241 | MEDIUM | 5.5 | 0.2% | Apr 23, 2024 | Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code o... |
| CVE-2024-32657 | MEDIUM | 5.4 | 0.5% | Apr 22, 2024 | Hydra is a Continuous Integration service for Nix based projects. Attackers can execute arbitrary code in the browser co... |
| CVE-2024-32653 | MEDIUM | 6.1 | 0.2% | Apr 22, 2024 | jadx is a Dex to Java decompiler. Prior to version 1.5.0, the package name is not filtered before concatenation. This ... |
| CVE-2024-32479 | MEDIUM | 5.4 | 34.1% | Apr 22, 2024 | LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Prior to version 24.4.0, there is improper s... |
| CVE-2024-31036 | MEDIUM | 6.8 | 0.3% | Apr 22, 2024 | A heap-buffer-overflow vulnerability in the read_byte function in NanoMQ v.0.21.7 allows attackers to cause a denial of ... |
| CVE-2024-29368 | MEDIUM | 6.5 | 0.8% | Apr 22, 2024 | An arbitrary file upload vulnerability in the file handling module of moziloCMS v2.0 allows attackers to bypass extensio... |
| CVE-2024-29376 | MEDIUM | 6.4 | 0.4% | Apr 22, 2024 | Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book. |
| CVE-2024-28436 | MEDIUM | 6.1 | 0.6% | Apr 22, 2024 | Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DA... |
| CVE-2024-3645 | MEDIUM | 6.4 | 0.3% | Apr 22, 2024 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2024-27347 | MEDIUM | 5.3 | 1.0% | Apr 22, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: ... |
| CVE-2024-4026 | MEDIUM | 4.6 | 0.3% | Apr 22, 2024 | Cross-Site Scripting (XSS) vulnerability in the Holded application. This vulnerability could allow an attacker to store ... |
| CVE-2024-28717 | MEDIUM | 4.9 | 0.9% | Apr 22, 2024 | An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component. |
| CVE-2024-22856 | MEDIUM | 5.4 | 0.3% | Apr 22, 2024 | A SQL injection vulnerability via the Save Favorite Search function in Axefinance Axe Credit Portal >= v.3.0 allows auth... |
| CVE-2024-22815 | MEDIUM | 5.3 | 0.2% | Apr 22, 2024 | An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cau... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now