2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31230 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | Missing Authorization vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.This issue affec... |
| CVE-2024-3570 | MEDIUM | 5.4 | 0.3% | Apr 10, 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm rep... |
| CVE-2024-3388 | MEDIUM | 5 | 0.3% | Apr 10, 2024 | A vulnerability in the GlobalProtect Gateway in Palo Alto Networks PAN-OS software enables an authenticated attacker to ... |
| CVE-2024-3387 | MEDIUM | 5.9 | 0.2% | Apr 10, 2024 | A weak (low bit strength) device certificate in Palo Alto Networks Panorama software enables an attacker to perform a me... |
| CVE-2024-3386 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclus... |
| CVE-2024-31342 | MEDIUM | 6.5 | 0.5% | Apr 10, 2024 | Missing Authorization vulnerability in WPcloudgallery WordPress Gallery Exporter.This issue affects WordPress Gallery Ex... |
| CVE-2024-1625 | MEDIUM | 6.5 | 0.4% | Apr 10, 2024 | An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary application version 0.3.0, allow... |
| CVE-2024-1602 | MEDIUM | 6.1 | 0.7% | Apr 10, 2024 | parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The ... |
| CVE-2024-31874 | MEDIUM | 5.5 | 0.3% | Apr 10, 2024 | IBM Security Verify Access Appliance 10.0.0 through 10.0.7 uses uninitialized variables when deploying that could allow ... |
| CVE-2024-31353 | MEDIUM | 5.3 | 0.5% | Apr 10, 2024 | Insertion of Sensitive Information into Log File vulnerability in Tribulant Slideshow Gallery.This issue affects Slidesh... |
| CVE-2024-31302 | MEDIUM | 5.3 | 0.5% | Apr 10, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodePeople Contact Form Email.This issue aff... |
| CVE-2024-31297 | MEDIUM | 5.3 | 0.4% | Apr 10, 2024 | Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce:... |
| CVE-2024-31287 | MEDIUM | 6.5 | 0.7% | Apr 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Librar... |
| CVE-2024-31282 | MEDIUM | 6.1 | 0.3% | Apr 10, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Buil... |
| CVE-2024-31278 | MEDIUM | 6.5 | 0.5% | Apr 10, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in Leap13 Premium Addons for Elementor premium-addons-fo... |
| CVE-2024-31253 | MEDIUM | 6.1 | 0.4% | Apr 10, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAu... |
| CVE-2024-23735 | MEDIUM | 6.1 | 0.2% | Apr 10, 2024 | Cross Site Scripting (XSS) vulnerability in in the S/MIME certificate upload functionality of the User Profile pages in ... |
| CVE-2024-23734 | MEDIUM | 5.2 | 0.1% | Apr 10, 2024 | Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify ... |
| CVE-2024-3567 | MEDIUM | 5.5 | 0.4% | Apr 10, 2024 | A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c... |
| CVE-2024-29296 | MEDIUM | 5.3 | 1.3% | Apr 10, 2024 | A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process,... |
| CVE-2024-27477 | MEDIUM | 6.1 | 0.6% | Apr 10, 2024 | In Leantime 3.0.6, a Cross-Site Scripting vulnerability exists within the ticket creation and modification functionality... |
| CVE-2024-27476 | MEDIUM | 4.7 | 0.6% | Apr 10, 2024 | Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket. |
| CVE-2024-3448 | MEDIUM | 5 | 0.4% | Apr 10, 2024 | Users with low privileges can perform certain AJAX actions. In this vulnerability instance, improper access to ajax?act... |
| CVE-2024-2731 | MEDIUM | 5.4 | 0.4% | Apr 10, 2024 | Users with low privileges (all permissions deselected in the administrator permissions settings) can view certain pages ... |
| CVE-2024-2730 | MEDIUM | 5.3 | 0.5% | Apr 10, 2024 | Mautic uses predictable page indices for unpublished landing pages, their content can be accessed by unauthenticated use... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now