2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-24488 | MEDIUM | 5.5 | 0.2% | Feb 7, 2024 | An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive informatio... |
| CVE-2024-23769 | MEDIUM | 5.5 | 0.2% | Feb 7, 2024 | Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacke... |
| CVE-2024-24823 | MEDIUM | 4.4 | 0.4% | Feb 7, 2024 | Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, re... |
| CVE-2024-24816 | MEDIUM | 6.1 | 1.7% | Feb 7, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability... |
| CVE-2024-24706 | MEDIUM | 4.3 | 0.2% | Feb 7, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1... |
| CVE-2024-23806 | MEDIUM | 5.3 | 0.3% | Feb 7, 2024 | Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device ... |
| CVE-2024-24815 | MEDIUM | 6.1 | 0.7% | Feb 7, 2024 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been disc... |
| CVE-2024-25145 | MEDIUM | 5.4 | 0.6% | Feb 7, 2024 | Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 ... |
| CVE-2024-25143 | MEDIUM | 6.5 | 0.7% | Feb 7, 2024 | The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3... |
| CVE-2024-24812 | MEDIUM | 5.4 | 0.4% | Feb 7, 2024 | Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrate... |
| CVE-2024-24771 | MEDIUM | 5.9 | 0.6% | Feb 7, 2024 | Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-e... |
| CVE-2024-24131 | MEDIUM | 6.1 | 0.9% | Feb 7, 2024 | SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp... |
| CVE-2024-24130 | MEDIUM | 6.1 | 0.4% | Feb 7, 2024 | Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability vi... |
| CVE-2024-1110 | MEDIUM | 5.3 | 0.5% | Feb 7, 2024 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-1109 | MEDIUM | 5.3 | 0.6% | Feb 7, 2024 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2024-1079 | MEDIUM | 5.3 | 0.5% | Feb 7, 2024 | The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th... |
| CVE-2024-1078 | MEDIUM | 4.3 | 0.4% | Feb 7, 2024 | The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-0977 | MEDIUM | 5.4 | 0.3% | Feb 7, 2024 | The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerabl... |
| CVE-2024-1055 | MEDIUM | 5.4 | 0.4% | Feb 7, 2024 | The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored... |
| CVE-2024-1037 | MEDIUM | 6.1 | 0.6% | Feb 7, 2024 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Script... |
| CVE-2024-0256 | MEDIUM | 5.4 | 0.3% | Feb 7, 2024 | The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Se... |
| CVE-2024-23447 | MEDIUM | 6.5 | 0.4% | Feb 7, 2024 | An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions ... |
| CVE-2024-23446 | MEDIUM | 6.5 | 0.5% | Feb 7, 2024 | An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DL... |
| CVE-2024-0849 | MEDIUM | 5 | 0.2% | Feb 7, 2024 | Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to ... |
| CVE-2024-1269 | MEDIUM | 6.1 | 0.7% | Feb 7, 2024 | A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulne... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now