2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22813 | MEDIUM | 4.4 | 0.4% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP addres... |
| CVE-2024-22809 | MEDIUM | 6.5 | 0.3% | Apr 22, 2024 | Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code... |
| CVE-2024-22807 | MEDIUM | 6.5 | 0.4% | Apr 22, 2024 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the fl... |
| CVE-2024-32691 | MEDIUM | 5.3 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in realmag777 Active Products Tables for WooCommerce.This issue affects Active Produ... |
| CVE-2024-32688 | MEDIUM | 6.5 | 0.5% | Apr 22, 2024 | Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0. |
| CVE-2024-32687 | MEDIUM | 4.3 | 0.4% | Apr 22, 2024 | Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce.This issue affects WPC Fr... |
| CVE-2024-32698 | MEDIUM | 5.4 | 0.3% | Apr 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy... |
| CVE-2024-32697 | MEDIUM | 6.5 | 0.3% | Apr 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso allows S... |
| CVE-2024-32696 | MEDIUM | 6.5 | 0.3% | Apr 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infog... |
| CVE-2024-32690 | MEDIUM | 5.9 | 0.3% | Apr 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS ... |
| CVE-2024-30799 | MEDIUM | 4.4 | 0.3% | Apr 22, 2024 | An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of serv... |
| CVE-2024-28722 | MEDIUM | 6.3 | 0.6% | Apr 22, 2024 | Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbit... |
| CVE-2024-29217 | MEDIUM | 4.6 | 1.0% | Apr 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This... |
| CVE-2024-4022 | MEDIUM | 5.3 | 0.6% | Apr 21, 2024 | A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been rated a... |
| CVE-2024-4021 | MEDIUM | 5.3 | 0.6% | Apr 21, 2024 | A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been declare... |
| CVE-2024-4019 | MEDIUM | 6.3 | 1.0% | Apr 20, 2024 | A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected i... |
| CVE-2024-4014 | MEDIUM | 6.4 | 0.3% | Apr 20, 2024 | The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptc... |
| CVE-2024-1730 | MEDIUM | 5.4 | 0.3% | Apr 20, 2024 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slid... |
| CVE-2024-1057 | MEDIUM | 5.4 | 0.3% | Apr 20, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-31994 | MEDIUM | 6.5 | 0.3% | Apr 19, 2024 | Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an a... |
| CVE-2024-32392 | MEDIUM | 4.5 | 0.8% | Apr 19, 2024 | Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functio... |
| CVE-2024-31993 | MEDIUM | 4.5 | 0.4% | Apr 19, 2024 | Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an imag... |
| CVE-2024-31992 | MEDIUM | 6.5 | 0.7% | Apr 19, 2024 | Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-c... |
| CVE-2024-31584 | MEDIUM | 5.5 | 0.4% | Apr 19, 2024 | Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.... |
| CVE-2024-1681 | MEDIUM | 5.3 | 0.6% | Apr 19, 2024 | corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake lo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now