2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-26466 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform... |
| CVE-2024-26465 | MEDIUM | 6.1 | 0.4% | Feb 26, 2024 | A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before... |
| CVE-2024-25763 | MEDIUM | 5.5 | 0.5% | Feb 26, 2024 | openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c. |
| CVE-2024-25410 | MEDIUM | 6.5 | 0.6% | Feb 26, 2024 | flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php. |
| CVE-2024-25344 | MEDIUM | 6.1 | 0.7% | Feb 26, 2024 | Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remto... |
| CVE-2024-25082 | MEDIUM | 6.5 | 1.9% | Feb 26, 2024 | Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. |
| CVE-2024-25081 | MEDIUM | 4.2 | 1.1% | Feb 26, 2024 | Splinefont in FontForge through 20230101 allows command injection via crafted filenames. |
| CVE-2024-24568 | MEDIUM | 5.3 | 0.6% | Feb 26, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. P... |
| CVE-2024-1890 | MEDIUM | 5.4 | 0.5% | Feb 26, 2024 | Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote att... |
| CVE-2024-1871 | MEDIUM | 5.4 | 0.5% | Feb 26, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affect... |
| CVE-2024-1436 | MEDIUM | 5.3 | 0.4% | Feb 26, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, S... |
| CVE-2024-1165 | MEDIUM | 6.5 | 0.8% | Feb 26, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including,... |
| CVE-2024-0798 | MEDIUM | 6.5 | 0.6% | Feb 26, 2024 | A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete ... |
| CVE-2024-0440 | MEDIUM | 6.5 | 0.6% | Feb 26, 2024 | Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protoco... |
| CVE-2024-0436 | MEDIUM | 5.9 | 0.5% | Feb 26, 2024 | Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password ... |
| CVE-2024-0435 | MEDIUM | 5.4 | 0.5% | Feb 26, 2024 | User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page lo... |
| CVE-2024-0387 | MEDIUM | 6.5 | 0.5% | Feb 26, 2024 | The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An atta... |
| CVE-2024-21501 | MEDIUM | 5.3 | 1.0% | Feb 24, 2024 | Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and ... |
| CVE-2024-1810 | MEDIUM | 6.1 | 0.4% | Feb 24, 2024 | The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s... |
| CVE-2024-22395 | MEDIUM | 6.3 | 0.4% | Feb 24, 2024 | Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific... |
| CVE-2024-26188 | MEDIUM | 4.3 | 0.8% | Feb 23, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-21423 | MEDIUM | 4.8 | 0.6% | Feb 23, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability |
| CVE-2024-1834 | MEDIUM | 6.1 | 0.6% | Feb 23, 2024 | A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as problematic.... |
| CVE-2024-1825 | MEDIUM | 6.1 | 0.5% | Feb 23, 2024 | A vulnerability, which was classified as problematic, was found in CodeAstro House Rental Management System 1.0. This af... |
| CVE-2024-1823 | MEDIUM | 5.3 | 0.7% | Feb 23, 2024 | A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now