2024 CVE Vulnerabilities
39,233 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21001 | MEDIUM | 5.4 | 0.4% | Apr 16, 2024 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform... |
| CVE-2024-20998 | MEDIUM | 4.9 | 1.0% | Apr 16, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2024-20994 | MEDIUM | 5.3 | 1.0% | Apr 16, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t... |
| CVE-2024-20993 | MEDIUM | 4.9 | 1.1% | Apr 16, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a... |
| CVE-2024-20992 | MEDIUM | 4.4 | 0.3% | Apr 16, 2024 | Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Content integration). The... |
| CVE-2024-20991 | MEDIUM | 5.3 | 0.6% | Apr 16, 2024 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). The supported v... |
| CVE-2024-20990 | MEDIUM | 5.3 | 0.5% | Apr 16, 2024 | Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Templates). Supporte... |
| CVE-2024-30378 | MEDIUM | 6.9 | 0.2% | Apr 16, 2024 | A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authentic... |
| CVE-2024-32455 | MEDIUM | 4.3 | 0.3% | Apr 16, 2024 | Missing Authorization vulnerability in Very Good Plugins Fatal Error Notify.This issue affects Fatal Error Notify: from ... |
| CVE-2024-3873 | MEDIUM | 4.3 | 0.3% | Apr 16, 2024 | A vulnerability was found in SMI SMI-EX-5414W up to 1.0.03. It has been classified as problematic. This affects an unkno... |
| CVE-2024-3862 | MEDIUM | 5.3 | 0.4% | Apr 16, 2024 | The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a... |
| CVE-2024-3861 | MEDIUM | 4 | 0.2% | Apr 16, 2024 | If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and l... |
| CVE-2024-3860 | MEDIUM | 6.2 | 0.2% | Apr 16, 2024 | An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently tra... |
| CVE-2024-3859 | MEDIUM | 5.9 | 0.7% | Apr 16, 2024 | On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by... |
| CVE-2024-3855 | MEDIUM | 6.5 | 0.4% | Apr 16, 2024 | In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability ... |
| CVE-2024-32024 | MEDIUM | 6.5 | 0.7% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p... |
| CVE-2024-32023 | MEDIUM | 5.3 | 0.7% | Apr 16, 2024 | Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.p... |
| CVE-2024-31451 | MEDIUM | 5.3 | 0.6% | Apr 16, 2024 | DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.p... |
| CVE-2024-30256 | MEDIUM | 6.4 | 0.4% | Apr 16, 2024 | Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forger... |
| CVE-2024-3869 | MEDIUM | 4.3 | 0.5% | Apr 16, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ... |
| CVE-2024-3672 | MEDIUM | 5.4 | 0.3% | Apr 16, 2024 | The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'all-items' sh... |
| CVE-2024-3243 | MEDIUM | 4.3 | 0.4% | Apr 16, 2024 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized email sending due to a missing c... |
| CVE-2024-3367 | MEDIUM | 5.5 | 0.3% | Apr 16, 2024 | Argument injection in websphere_mq agent plugin in Checkmk 2.0.0, 2.1.0, <2.2.0p26 and <2.3.0b5 allows local attacker to... |
| CVE-2024-3867 | MEDIUM | 6.1 | 0.8% | Apr 16, 2024 | The archive-tainacan-collection theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad... |
| CVE-2024-1357 | MEDIUM | 5.4 | 0.4% | Apr 16, 2024 | The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now