2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27927 | MEDIUM | 6.5 | 1.0% | Mar 21, 2024 | RSSHub is an open source RSS feed generator. Prior to version 1.0.0-master.a429472, RSSHub allows remote attackers to us... |
| CVE-2024-27926 | MEDIUM | 6.1 | 0.5% | Mar 21, 2024 | RSSHub is an open source RSS feed generator. Starting in version 1.0.0-master.cbbd829 and prior to version 1.0.0-master.... |
| CVE-2024-27916 | MEDIUM | 4.3 | 0.7% | Mar 21, 2024 | Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRe... |
| CVE-2024-27626 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Dotclear version 2.29. The flaw exists withi... |
| CVE-2024-27291 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, it is possible to create a... |
| CVE-2024-27290 | MEDIUM | 6.1 | 0.4% | Mar 21, 2024 | Docassemble is an expert system for guided interviews and document assembly. Prior to 1.4.97, a user could type HTML int... |
| CVE-2024-27105 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed... |
| CVE-2024-26196 | MEDIUM | 4.3 | 1.2% | Mar 21, 2024 | Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-25811 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information. |
| CVE-2024-25359 | MEDIUM | 6.6 | 0.3% | Mar 21, 2024 | An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of ... |
| CVE-2024-25167 | MEDIUM | 6.1 | 0.6% | Mar 21, 2024 | Cross Site Scripting vulnerability in eblog v1.0 allows a remote attacker to execute arbitrary code via a crafted script... |
| CVE-2024-24818 | MEDIUM | 5.9 | 0.6% | Mar 21, 2024 | EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "P... |
| CVE-2024-24110 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | SQL Injection vulnerability in crmeb_java before v1.3.4 allows attackers to run arbitrary SQL commands via crafted GET r... |
| CVE-2024-24028 | MEDIUM | 5.9 | 0.2% | Mar 21, 2024 | Server Side Request Forgery (SSRF) vulnerability in Likeshop before 2.5.7 allows attackers to view sensitive information... |
| CVE-2024-22352 | MEDIUM | 5.5 | 0.5% | Mar 21, 2024 | IBM InfoSphere Information Server 11.7 stores potentially sensitive information in log files that could be read by a loc... |
| CVE-2024-1908 | MEDIUM | 6.5 | 0.6% | Mar 21, 2024 | An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to us... |
| CVE-2024-1503 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross-Site Request Forgery in... |
| CVE-2024-1502 | MEDIUM | 4.3 | 0.4% | Mar 21, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to unauthorized loss of data due... |
| CVE-2024-1450 | MEDIUM | 5.4 | 0.5% | Mar 21, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco... |
| CVE-2024-1326 | MEDIUM | 5.4 | 0.5% | Mar 21, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML Tag attributes in all v... |
| CVE-2024-1278 | MEDIUM | 5.4 | 0.4% | Mar 21, 2024 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-1214 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req... |
| CVE-2024-1213 | MEDIUM | 4.3 | 0.2% | Mar 21, 2024 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Cross-Site Req... |
| CVE-2024-1142 | MEDIUM | 5.4 | 0.7% | Mar 21, 2024 | Path Traversal in Sonatype IQ Server from version 143 allows remote authenticated attackers to overwrite or delete files... |
| CVE-2024-0966 | MEDIUM | 5.4 | 0.5% | Mar 21, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now