2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1767 | MEDIUM | 5.4 | 0.3% | Mar 9, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up ... |
| CVE-2024-1320 | MEDIUM | 6.1 | 0.4% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-1125 | MEDIUM | 5.4 | 0.3% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data d... |
| CVE-2024-1124 | MEDIUM | 4.3 | 0.3% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending ... |
| CVE-2024-1123 | MEDIUM | 6.5 | 0.4% | Mar 9, 2024 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification o... |
| CVE-2024-28180 | MEDIUM | 4.3 | 2.0% | Mar 9, 2024 | Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An atta... |
| CVE-2024-28176 | MEDIUM | 5.9 | 2.1% | Mar 9, 2024 | jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web ... |
| CVE-2024-28122 | MEDIUM | 6.8 | 0.6% | Mar 9, 2024 | JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerabili... |
| CVE-2024-28753 | MEDIUM | 6.5 | 0.7% | Mar 9, 2024 | RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request. |
| CVE-2024-21901 | MEDIUM | 4.7 | 18.7% | Mar 8, 2024 | A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authe... |
| CVE-2024-21900 | MEDIUM | 6.5 | 9.4% | Mar 8, 2024 | An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnera... |
| CVE-2024-2319 | MEDIUM | 6.1 | 0.4% | Mar 8, 2024 | Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could sto... |
| CVE-2024-2316 | MEDIUM | 4.3 | 0.4% | Mar 8, 2024 | A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnera... |
| CVE-2024-2298 | MEDIUM | 4.3 | 0.3% | Mar 8, 2024 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi... |
| CVE-2024-1851 | MEDIUM | 6.5 | 0.3% | Mar 8, 2024 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi... |
| CVE-2024-27612 | MEDIUM | 6.2 | 10.7% | Mar 8, 2024 | Numbas editor before 7.3 mishandles editing of themes and extensions. |
| CVE-2024-1987 | MEDIUM | 5.4 | 0.4% | Mar 8, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor... |
| CVE-2024-2285 | MEDIUM | 6.1 | 0.5% | Mar 8, 2024 | A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. A... |
| CVE-2024-2284 | MEDIUM | 6.1 | 0.5% | Mar 8, 2024 | A vulnerability classified as problematic was found in boyiddha Automated-Mess-Management-System 1.0. Affected by this v... |
| CVE-2024-2277 | MEDIUM | 4.3 | 0.3% | Mar 8, 2024 | A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problem... |
| CVE-2024-26313 | MEDIUM | 5.4 | 0.5% | Mar 8, 2024 | Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote... |
| CVE-2024-25848 | MEDIUM | 5.9 | 0.4% | Mar 8, 2024 | In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection ... |
| CVE-2024-23297 | MEDIUM | 5.5 | 0.3% | Mar 8, 2024 | The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. ... |
| CVE-2024-23295 | MEDIUM | 5.5 | 0.3% | Mar 8, 2024 | A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An ... |
| CVE-2024-23293 | MEDIUM | 4.6 | 0.4% | Mar 8, 2024 | This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonom... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now