2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27969 | MEDIUM | 6.5 | 0.3% | Apr 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Enhanced Free D... |
| CVE-2024-27966 | MEDIUM | 5.9 | 0.3% | Apr 11, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz A... |
| CVE-2024-25922 | MEDIUM | 5.4 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: ... |
| CVE-2024-25908 | MEDIUM | 4.3 | 0.3% | Apr 11, 2024 | Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5... |
| CVE-2024-25907 | MEDIUM | 5.4 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5... |
| CVE-2024-24883 | MEDIUM | 4.3 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad... |
| CVE-2024-24850 | MEDIUM | 5.3 | 0.4% | Apr 11, 2024 | Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Po... |
| CVE-2024-3613 | MEDIUM | 5.4 | 0.5% | Apr 11, 2024 | A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been rated as problematic. Affected ... |
| CVE-2024-3612 | MEDIUM | 5.4 | 0.5% | Apr 11, 2024 | A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been declared as problematic. Affect... |
| CVE-2024-32001 | MEDIUM | 4.3 | 0.6% | Apr 10, 2024 | SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form:... |
| CVE-2024-29902 | MEDIUM | 5.9 | 0.7% | Apr 10, 2024 | Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a... |
| CVE-2024-31995 | MEDIUM | 4.3 | 0.4% | Apr 10, 2024 | `@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.... |
| CVE-2024-31985 | MEDIUM | 5.4 | 0.3% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1... |
| CVE-2024-29460 | MEDIUM | 6.6 | 0.2% | Apr 10, 2024 | An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone vi... |
| CVE-2024-1481 | MEDIUM | 5.3 | 1.1% | Apr 10, 2024 | A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be ... |
| CVE-2024-31939 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Imp... |
| CVE-2024-29502 | MEDIUM | 6.5 | 0.7% | Apr 10, 2024 | An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC p... |
| CVE-2024-3516 | MEDIUM | 6.5 | 1.0% | Apr 10, 2024 | Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit ... |
| CVE-2024-3515 | MEDIUM | 6.5 | 0.8% | Apr 10, 2024 | Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-31464 | MEDIUM | 4.9 | 0.4% | Apr 10, 2024 | XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9... |
| CVE-2024-31386 | MEDIUM | 4.3 | 0.4% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Defaul... |
| CVE-2024-28345 | MEDIUM | 5.5 | 0.4% | Apr 10, 2024 | An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpo... |
| CVE-2024-31944 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This... |
| CVE-2024-31943 | MEDIUM | 4.3 | 0.2% | Apr 10, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affect... |
| CVE-2024-31242 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now