2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3600 | MEDIUM | 6.1 | 0.4% | Apr 19, 2024 | The Poll Maker – Best WordPress Poll Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a m... |
| CVE-2024-3598 | MEDIUM | 5.4 | 0.3% | Apr 19, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Creative Button w... |
| CVE-2024-3560 | MEDIUM | 5.4 | 0.3% | Apr 19, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _id valu... |
| CVE-2024-27978 | MEDIUM | 6.5 | 1.7% | Apr 19, 2024 | A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth... |
| CVE-2024-24991 | MEDIUM | 6.5 | 1.7% | Apr 19, 2024 | A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an auth... |
| CVE-2024-23533 | MEDIUM | 6.5 | 1.4% | Apr 19, 2024 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditi... |
| CVE-2024-21846 | MEDIUM | 6.9 | 0.5% | Apr 18, 2024 | An unauthenticated attacker can reset the board and stop transmitter operations by sending a specially-crafted GET requ... |
| CVE-2024-32473 | MEDIUM | 6.5 | 0.4% | Apr 18, 2024 | Moby is an open source container framework that is a key component of Docker Engine, Docker Desktop, and other distribut... |
| CVE-2024-30927 | MEDIUM | 6.3 | 0.6% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the racer-r... |
| CVE-2024-30926 | MEDIUM | 4.6 | 0.5% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the ./inc/k... |
| CVE-2024-30925 | MEDIUM | 6.5 | 0.6% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the photo-t... |
| CVE-2024-30924 | MEDIUM | 4.6 | 0.3% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin... |
| CVE-2024-30921 | MEDIUM | 5.4 | 0.6% | Apr 18, 2024 | Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-30107 | MEDIUM | 6.5 | 0.3% | Apr 18, 2024 | HCL Connections contains a broken access control vulnerability that may expose sensitive information to unauthorized use... |
| CVE-2024-32474 | MEDIUM | 6.5 | 0.4% | Apr 18, 2024 | Sentry is an error tracking and performance monitoring platform. Prior to 24.4.1, when authenticating as a superuser to ... |
| CVE-2024-29987 | MEDIUM | 6.5 | 1.2% | Apr 18, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-29986 | MEDIUM | 5.4 | 0.5% | Apr 18, 2024 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-23557 | MEDIUM | 4.3 | 0.3% | Apr 18, 2024 | HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the u... |
| CVE-2024-32335 | MEDIUM | 5.4 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Access Control under ... |
| CVE-2024-32334 | MEDIUM | 6.5 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in IP/Port Filtering und... |
| CVE-2024-32333 | MEDIUM | 4.3 | 0.6% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in MAC Filtering under t... |
| CVE-2024-32332 | MEDIUM | 6.1 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in WDS Settings under th... |
| CVE-2024-32327 | MEDIUM | 5.5 | 0.4% | Apr 18, 2024 | TOTOLINK N300RT V2.1.8-B20201030.1539 contains a Store Cross-site scripting (XSS) vulnerability in Port Forwarding under... |
| CVE-2024-32326 | MEDIUM | 6.8 | 0.6% | Apr 18, 2024 | TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in t... |
| CVE-2024-32470 | MEDIUM | 6.5 | 0.6% | Apr 18, 2024 | Tolgee is an open-source localization platform. When API key created by admin user is used it bypasses the permission ch... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now