2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-2395 | MEDIUM | 4.3 | 0.2% | Mar 12, 2024 | The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2024-0386 | MEDIUM | 6.1 | 0.6% | Mar 12, 2024 | The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versi... |
| CVE-2024-28239 | MEDIUM | 4.3 | 0.6% | Mar 12, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect`... |
| CVE-2024-28236 | MEDIUM | 6.5 | 0.7% | Mar 12, 2024 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines ca... |
| CVE-2024-27305 | MEDIUM | 5.3 | 0.4% | Mar 12, 2024 | aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP sm... |
| CVE-2024-24097 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary... |
| CVE-2024-2130 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versio... |
| CVE-2024-2031 | MEDIUM | 5.4 | 0.3% | Mar 12, 2024 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoo... |
| CVE-2024-28113 | MEDIUM | 6.1 | 0.4% | Mar 12, 2024 | Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arb... |
| CVE-2024-28112 | MEDIUM | 4.8 | 0.3% | Mar 12, 2024 | Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored... |
| CVE-2024-28098 | MEDIUM | 5.4 | 1.7% | Mar 12, 2024 | The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, su... |
| CVE-2024-1410 | MEDIUM | 5.3 | 0.7% | Mar 12, 2024 | Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retiremen... |
| CVE-2024-1137 | MEDIUM | 4.3 | 0.3% | Mar 12, 2024 | The Proxy and Client components of TIBCO Software Inc.'s TIBCO ActiveSpaces - Enterprise Edition contain a vulnerability... |
| CVE-2024-2182 | MEDIUM | 6.5 | 0.8% | Mar 12, 2024 | A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high avail... |
| CVE-2024-28339 | MEDIUM | 5.4 | 0.4% | Mar 12, 2024 | An information leak in the debuginfo.htm component of Netgear CBR40 2.5.0.28, Netgear CBK40 2.5.0.28, and Netgear CBK43 ... |
| CVE-2024-26201 | MEDIUM | 6.6 | 0.9% | Mar 12, 2024 | Microsoft Intune Linux Agent Elevation of Privilege Vulnerability |
| CVE-2024-26197 | MEDIUM | 6.5 | 2.9% | Mar 12, 2024 | Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
| CVE-2024-26185 | MEDIUM | 6.5 | 30.5% | Mar 12, 2024 | Windows Compressed Folder Tampering Vulnerability |
| CVE-2024-26181 | MEDIUM | 5.5 | 1.0% | Mar 12, 2024 | Windows Kernel Denial of Service Vulnerability |
| CVE-2024-26177 | MEDIUM | 5.5 | 1.1% | Mar 12, 2024 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2024-26174 | MEDIUM | 5.5 | 0.9% | Mar 12, 2024 | Windows Kernel Information Disclosure Vulnerability |
| CVE-2024-26160 | MEDIUM | 5.5 | 11.4% | Mar 12, 2024 | Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability |
| CVE-2024-21448 | MEDIUM | 5 | 1.2% | Mar 12, 2024 | Microsoft Teams for Android Information Disclosure Vulnerability |
| CVE-2024-21431 | MEDIUM | 6.7 | 0.6% | Mar 12, 2024 | Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability |
| CVE-2024-21430 | MEDIUM | 6.4 | 0.7% | Mar 12, 2024 | Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now