2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30203 | MEDIUM | 5.5 | 0.6% | Mar 25, 2024 | In Emacs before 29.3, Gnus treats inline MIME contents as trusted. |
| CVE-2024-28183 | MEDIUM | 5.7 | 0.2% | Mar 25, 2024 | ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-o... |
| CVE-2024-25175 | MEDIUM | 6.1 | 0.4% | Mar 25, 2024 | An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack. |
| CVE-2024-28435 | MEDIUM | 5.4 | 0.4% | Mar 25, 2024 | The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload. |
| CVE-2024-2864 | MEDIUM | 6.1 | 0.4% | Mar 25, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify ... |
| CVE-2024-30187 | MEDIUM | 5.3 | 0.5% | Mar 25, 2024 | Anope before 2.0.15 does not prevent resetting the password of a suspended account. |
| CVE-2024-29216 | MEDIUM | 6.1 | 0.2% | Mar 25, 2024 | Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOC... |
| CVE-2024-29009 | MEDIUM | 6.1 | 0.2% | Mar 25, 2024 | Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker... |
| CVE-2024-21865 | MEDIUM | 6.5 | 0.4% | Mar 25, 2024 | HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at... |
| CVE-2024-1564 | MEDIUM | 4.3 | 0.5% | Mar 25, 2024 | The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access cus... |
| CVE-2024-1232 | MEDIUM | 4.8 | 0.2% | Mar 25, 2024 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac... |
| CVE-2024-1231 | MEDIUM | 6.8 | 0.2% | Mar 25, 2024 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac... |
| CVE-2024-29034 | MEDIUM | 6.1 | 0.4% | Mar 24, 2024 | CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-... |
| CVE-2024-30161 | MEDIUM | 6.5 | 0.5% | Mar 24, 2024 | In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly ... |
| CVE-2024-24840 | MEDIUM | 5.4 | 0.3% | Mar 23, 2024 | Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor ... |
| CVE-2024-24835 | MEDIUM | 6.5 | 0.4% | Mar 23, 2024 | Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4. |
| CVE-2024-2832 | MEDIUM | 6.1 | 0.5% | Mar 23, 2024 | A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects ... |
| CVE-2024-2326 | MEDIUM | 4.3 | 0.2% | Mar 23, 2024 | The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable t... |
| CVE-2024-1049 | MEDIUM | 5.4 | 0.3% | Mar 23, 2024 | The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-2688 | MEDIUM | 5.4 | 0.3% | Mar 23, 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute... |
| CVE-2024-2468 | MEDIUM | 5.4 | 0.3% | Mar 23, 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute... |
| CVE-2024-2202 | MEDIUM | 5.4 | 0.4% | Mar 23, 2024 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image wi... |
| CVE-2024-2131 | MEDIUM | 5.4 | 0.3% | Mar 23, 2024 | The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox... |
| CVE-2024-1697 | MEDIUM | 5.4 | 0.4% | Mar 23, 2024 | The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-29057 | MEDIUM | 4.3 | 1.0% | Mar 22, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now