2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-22307 | MEDIUM | 6.1 | 0.3% | Jan 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister L... |
| CVE-2024-22306 | MEDIUM | 4.8 | 0.3% | Jan 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hometory Mang Boar... |
| CVE-2024-22302 | MEDIUM | 5.4 | 0.3% | Jan 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ignazio Scimone Al... |
| CVE-2024-23508 | MEDIUM | 6.1 | 0.3% | Jan 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins PDF Poste... |
| CVE-2024-23505 | MEDIUM | 5.4 | 0.3% | Jan 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DearHive PDF Viewe... |
| CVE-2024-23502 | MEDIUM | 5.4 | 0.3% | Jan 31, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in InfornWeb Posts Li... |
| CVE-2024-1103 | MEDIUM | 5.4 | 0.6% | Jan 31, 2024 | A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by ... |
| CVE-2024-0589 | MEDIUM | 5.4 | 0.3% | Jan 31, 2024 | Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and e... |
| CVE-2024-22287 | MEDIUM | 6.1 | 0.2% | Jan 31, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).... |
| CVE-2024-1099 | MEDIUM | 5.4 | 0.6% | Jan 31, 2024 | A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFil... |
| CVE-2024-23170 | MEDIUM | 5.5 | 0.3% | Jan 31, 2024 | An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA priva... |
| CVE-2024-0836 | MEDIUM | 4.3 | 0.4% | Jan 31, 2024 | The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized m... |
| CVE-2024-22236 | MEDIUM | 5.5 | 0.2% | Jan 31, 2024 | In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.... |
| CVE-2024-0914 | MEDIUM | 5.9 | 0.9% | Jan 31, 2024 | A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 pad... |
| CVE-2024-22569 | MEDIUM | 5.4 | 0.5% | Jan 31, 2024 | Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a craft... |
| CVE-2024-23834 | MEDIUM | 6.1 | 0.5% | Jan 30, 2024 | Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in s... |
| CVE-2024-24567 | MEDIUM | 5.3 | 0.5% | Jan 30, 2024 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in b... |
| CVE-2024-24558 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tans... |
| CVE-2024-24556 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable t... |
| CVE-2024-23841 | MEDIUM | 6.1 | 0.4% | Jan 30, 2024 | apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nex... |
| CVE-2024-21388 | MEDIUM | 6.5 | 32.0% | Jan 30, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
| CVE-2024-24565 | MEDIUM | 6.5 | 3.1% | Jan 30, 2024 | CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. Th... |
| CVE-2024-23840 | MEDIUM | 5.5 | 0.3% | Jan 30, 2024 | GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a ta... |
| CVE-2024-23825 | MEDIUM | 4.9 | 0.5% | Jan 30, 2024 | TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL... |
| CVE-2024-22200 | MEDIUM | 5.3 | 0.3% | Jan 30, 2024 | vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now