2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1687 | MEDIUM | 5.4 | 0.4% | Feb 27, 2024 | The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to unauthorized e... |
| CVE-2024-1686 | MEDIUM | 4.3 | 0.4% | Feb 27, 2024 | The Thank You Page Customizer for WooCommerce – Increase Your Sales plugin for WordPress is vulnerable to missing author... |
| CVE-2024-1323 | MEDIUM | 5.4 | 0.5% | Feb 27, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Post Type ... |
| CVE-2024-24099 | MEDIUM | 5.4 | 0.4% | Feb 27, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update. |
| CVE-2024-25166 | MEDIUM | 6.1 | 0.5% | Feb 27, 2024 | Cross Site Scripting vulnerability in 71CMS v.1.0.0 allows a remote attacker to execute arbitrary code via the uploadfil... |
| CVE-2024-24720 | MEDIUM | 5.3 | 0.5% | Feb 27, 2024 | An issue was discovered in the Forgot password function in Innovaphone PBX before 14r1 devices. It provides information ... |
| CVE-2024-22543 | MEDIUM | 6.1 | 1.2% | Feb 27, 2024 | An issue was discovered in Linksys Router E1700 1.0.04 (build 3), allows authenticated attackers to escalate privileges ... |
| CVE-2024-24721 | MEDIUM | 6.5 | 0.3% | Feb 27, 2024 | An issue was discovered on Innovaphone PBX before 14r1 devices. The password form, used to authenticate, allows a Brute ... |
| CVE-2024-26149 | MEDIUM | 5.3 | 0.5% | Feb 26, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified... |
| CVE-2024-24564 | MEDIUM | 5.3 | 0.6% | Feb 26, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, star... |
| CVE-2024-1899 | MEDIUM | 5.3 | 0.8% | Feb 26, 2024 | An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of servi... |
| CVE-2024-25770 | MEDIUM | 4.3 | 0.6% | Feb 26, 2024 | libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. |
| CVE-2024-27088 | MEDIUM | 5.5 | 0.5% | Feb 26, 2024 | es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into ... |
| CVE-2024-27087 | MEDIUM | 5.4 | 0.3% | Feb 26, 2024 | Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that ... |
| CVE-2024-25767 | MEDIUM | 6.5 | 0.6% | Feb 26, 2024 | nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c. |
| CVE-2024-27350 | MEDIUM | 5.9 | 0.3% | Feb 26, 2024 | Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug B... |
| CVE-2024-26606 | MEDIUM | 5.5 | 0.2% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)po... |
| CVE-2024-26605 | MEDIUM | 5.5 | 0.2% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last m... |
| CVE-2024-26604 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whethe... |
| CVE-2024-26603 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to faul... |
| CVE-2024-26602 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on s... |
| CVE-2024-26601 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed i... |
| CVE-2024-26600 | MEDIUM | 5.5 | 0.3% | Feb 26, 2024 | In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereferenc... |
| CVE-2024-26468 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b6... |
| CVE-2024-26467 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams befo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now