2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26559 | MEDIUM | 5.3 | 0.7% | Feb 28, 2024 | An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information. |
| CVE-2024-25579 | MEDIUM | 6.8 | 0.8% | Feb 28, 2024 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat... |
| CVE-2024-22532 | MEDIUM | 6.5 | 1.1% | Feb 28, 2024 | Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service v... |
| CVE-2024-21798 | MEDIUM | 4.8 | 1.3% | Feb 28, 2024 | ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user co... |
| CVE-2024-26450 | MEDIUM | 5.4 | 0.2% | Feb 28, 2024 | An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit invol... |
| CVE-2024-25868 | MEDIUM | 6.1 | 0.6% | Feb 28, 2024 | A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attack... |
| CVE-2024-1972 | MEDIUM | 5.4 | 0.5% | Feb 28, 2024 | A vulnerability was found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this issue ... |
| CVE-2024-27285 | MEDIUM | 6.1 | 1.1% | Feb 28, 2024 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to... |
| CVE-2024-25435 | MEDIUM | 6.1 | 0.4% | Feb 28, 2024 | A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scri... |
| CVE-2024-25202 | MEDIUM | 6.1 | 1.0% | Feb 28, 2024 | Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attacke... |
| CVE-2024-27103 | MEDIUM | 6.1 | 0.4% | Feb 28, 2024 | Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search resu... |
| CVE-2024-0560 | MEDIUM | 4.3 | 0.5% | Feb 28, 2024 | A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is us... |
| CVE-2024-24705 | MEDIUM | 5.4 | 0.2% | Feb 28, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a th... |
| CVE-2024-1965 | MEDIUM | 5.3 | 0.4% | Feb 28, 2024 | Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could ... |
| CVE-2024-1808 | MEDIUM | 5.4 | 0.3% | Feb 28, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-26016 | MEDIUM | 5.4 | 0.9% | Feb 28, 2024 | A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then ... |
| CVE-2024-24779 | MEDIUM | 6.5 | 0.7% | Feb 28, 2024 | Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows fo... |
| CVE-2024-24773 | MEDIUM | 6.5 | 0.8% | Feb 28, 2024 | Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization ... |
| CVE-2024-24772 | MEDIUM | 4.3 | 0.9% | Feb 28, 2024 | A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information ... |
| CVE-2024-1636 | MEDIUM | 5.4 | 0.4% | Feb 28, 2024 | Potential Cross-Site Scripting (XSS) in the page editing area. |
| CVE-2024-1632 | MEDIUM | 6.5 | 0.5% | Feb 28, 2024 | Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrati... |
| CVE-2024-27315 | MEDIUM | 4.3 | 1.0% | Feb 28, 2024 | An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially cr... |
| CVE-2024-1861 | MEDIUM | 4.3 | 0.4% | Feb 28, 2024 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v... |
| CVE-2024-1860 | MEDIUM | 5.3 | 0.4% | Feb 28, 2024 | The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v... |
| CVE-2024-1719 | MEDIUM | 4.3 | 0.3% | Feb 28, 2024 | The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now