2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26247 | MEDIUM | 4.7 | 1.1% | Mar 22, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
| CVE-2024-2824 | MEDIUM | 6.3 | 0.7% | Mar 22, 2024 | A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function Prin... |
| CVE-2024-2823 | MEDIUM | 4.3 | 0.4% | Mar 22, 2024 | A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of ... |
| CVE-2024-2822 | MEDIUM | 4.3 | 0.4% | Mar 22, 2024 | A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file... |
| CVE-2024-29186 | MEDIUM | 5.3 | 0.7% | Mar 22, 2024 | Bref is an open-source project that helps users go serverless on Amazon Web Services with PHP. When Bref prior to versio... |
| CVE-2024-29042 | MEDIUM | 5.3 | 0.7% | Mar 22, 2024 | Translate is a package that allows users to convert text to different languages on Node.js and the browser. Prior to ver... |
| CVE-2024-2821 | MEDIUM | 4.3 | 0.4% | Mar 22, 2024 | A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. Affected by this issue is some unkn... |
| CVE-2024-2820 | MEDIUM | 4.3 | 0.4% | Mar 22, 2024 | A vulnerability classified as problematic was found in DedeCMS 5.7. Affected by this vulnerability is an unknown functio... |
| CVE-2024-29865 | MEDIUM | 5.4 | 0.3% | Mar 22, 2024 | Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. |
| CVE-2024-28593 | MEDIUM | 5.4 | 0.6% | Mar 22, 2024 | The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTM... |
| CVE-2024-2728 | MEDIUM | 5.5 | 0.2% | Mar 22, 2024 | Information exposure vulnerability in the CIGESv2 system. This vulnerability could allow a local attacker to intercept t... |
| CVE-2024-2727 | MEDIUM | 6.1 | 0.3% | Mar 22, 2024 | HTML injection vulnerability affecting the CIGESv2 system, which allows an attacker to inject arbitrary code and modify ... |
| CVE-2024-2726 | MEDIUM | 6.1 | 0.3% | Mar 22, 2024 | Stored Cross-Site Scripting (Stored-XSS) vulnerability affecting the CIGESv2 system, allowing an attacker to execute and... |
| CVE-2024-28560 | MEDIUM | 5.4 | 0.5% | Mar 22, 2024 | SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the delete... |
| CVE-2024-25168 | MEDIUM | 6.3 | 0.6% | Mar 22, 2024 | SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope pa... |
| CVE-2024-0638 | MEDIUM | 6.7 | 0.2% | Mar 22, 2024 | Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b... |
| CVE-2024-2817 | MEDIUM | 6.5 | 0.3% | Mar 22, 2024 | A vulnerability, which was classified as problematic, has been found in Tenda AC15 15.03.05.18. Affected by this issue i... |
| CVE-2024-2816 | MEDIUM | 6.5 | 0.4% | Mar 22, 2024 | A vulnerability classified as problematic was found in Tenda AC15 15.03.05.18. Affected by this vulnerability is the fun... |
| CVE-2024-29273 | MEDIUM | 6.1 | 0.4% | Mar 22, 2024 | There is Stored Cross-Site Scripting (XSS) in dzzoffice 2.02.1 SC UTF8 in uploadfile to index.php, with the XSS payload ... |
| CVE-2024-29272 | MEDIUM | 6.5 | 9.4% | Mar 22, 2024 | Arbitrary File Upload vulnerability in VvvebJs before version 1.7.5, allows unauthenticated remote attackers to execute ... |
| CVE-2024-29271 | MEDIUM | 6.1 | 0.6% | Mar 22, 2024 | Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute a... |
| CVE-2024-26557 | MEDIUM | 5.4 | 0.3% | Mar 22, 2024 | Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter. |
| CVE-2024-25807 | MEDIUM | 6.1 | 0.5% | Mar 22, 2024 | Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain s... |
| CVE-2024-2780 | MEDIUM | 6.1 | 0.5% | Mar 22, 2024 | A vulnerability was found in Campcodes Online Marriage Registration System 1.0. It has been declared as problematic. Thi... |
| CVE-2024-2500 | MEDIUM | 6.4 | 0.4% | Mar 22, 2024 | The ColorMag theme for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now