2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-28782 | MEDIUM | 6.5 | 0.4% | Apr 3, 2024 | IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores u... |
| CVE-2024-28589 | MEDIUM | 6.7 | 0.3% | Apr 3, 2024 | An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attac... |
| CVE-2024-24506 | MEDIUM | 6.1 | 0.7% | Apr 3, 2024 | Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attacke... |
| CVE-2024-31008 | MEDIUM | 6.5 | 0.7% | Apr 3, 2024 | An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive inf... |
| CVE-2024-2322 | MEDIUM | 6.8 | 0.4% | Apr 3, 2024 | The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, w... |
| CVE-2024-31013 | MEDIUM | 6.1 | 0.5% | Apr 3, 2024 | Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via ... |
| CVE-2024-31009 | MEDIUM | 6.5 | 0.7% | Apr 3, 2024 | SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter... |
| CVE-2024-3162 | MEDIUM | 5.4 | 0.3% | Apr 3, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attri... |
| CVE-2024-28836 | MEDIUM | 5.4 | 0.4% | Apr 3, 2024 | An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall... |
| CVE-2024-28755 | MEDIUM | 6.5 | 0.4% | Apr 3, 2024 | An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset... |
| CVE-2024-28219 | MEDIUM | 5.9 | 1.0% | Apr 3, 2024 | In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. |
| CVE-2024-26495 | MEDIUM | 6.1 | 0.5% | Apr 3, 2024 | Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbi... |
| CVE-2024-1327 | MEDIUM | 5.4 | 0.3% | Apr 3, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widge... |
| CVE-2024-3225 | MEDIUM | 6.5 | 0.6% | Apr 3, 2024 | A vulnerability was found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this ... |
| CVE-2024-3218 | MEDIUM | 5.4 | 0.7% | Apr 3, 2024 | A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System ... |
| CVE-2024-3248 | MEDIUM | 5.5 | 0.3% | Apr 2, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow. |
| CVE-2024-3247 | MEDIUM | 5.5 | 0.3% | Apr 2, 2024 | In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow. |
| CVE-2024-3202 | MEDIUM | 5.9 | 1.2% | Apr 2, 2024 | A vulnerability, which was classified as problematic, has been found in codelyfe Stupid Simple CMS 1.2.4. This issue aff... |
| CVE-2024-30370 | MEDIUM | 4.3 | 1.2% | Apr 2, 2024 | RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The... |
| CVE-2024-30363 | MEDIUM | 5.5 | 0.7% | Apr 2, 2024 | Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows rem... |
| CVE-2024-25075 | MEDIUM | 5.1 | 0.2% | Apr 2, 2024 | An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotification... |
| CVE-2024-29834 | MEDIUM | 6.4 | 1.4% | Apr 2, 2024 | This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on ... |
| CVE-2024-30532 | MEDIUM | 4.9 | 0.3% | Apr 2, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects ... |
| CVE-2024-30531 | MEDIUM | 4.9 | 0.3% | Apr 2, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from ... |
| CVE-2024-24888 | MEDIUM | 6.5 | 0.3% | Apr 2, 2024 | Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This iss... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now