2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23441 | MEDIUM | 5.5 | 0.2% | Jan 29, 2024 | Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the ... |
| CVE-2024-1006 | MEDIUM | 5.3 | 0.7% | Jan 29, 2024 | A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affec... |
| CVE-2024-22559 | MEDIUM | 5.4 | 0.3% | Jan 29, 2024 | LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field. |
| CVE-2024-23792 | MEDIUM | 6.5 | 0.3% | Jan 29, 2024 | When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. Th... |
| CVE-2024-0212 | MEDIUM | 6.5 | 0.8% | Jan 29, 2024 | The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attacke... |
| CVE-2024-23782 | MEDIUM | 5.4 | 0.3% | Jan 28, 2024 | Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series v... |
| CVE-2024-0958 | MEDIUM | 5.4 | 0.6% | Jan 27, 2024 | A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects som... |
| CVE-2024-0618 | MEDIUM | 4.8 | 0.5% | Jan 27, 2024 | The Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms plugin for WordPress is vuln... |
| CVE-2024-0824 | MEDIUM | 5.4 | 0.3% | Jan 27, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Anythi... |
| CVE-2024-0697 | MEDIUM | 4.9 | 0.8% | Jan 27, 2024 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Directory Traversal in all versi... |
| CVE-2024-0667 | MEDIUM | 6.3 | 0.2% | Jan 27, 2024 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Cross-S... |
| CVE-2024-0664 | MEDIUM | 4.8 | 0.3% | Jan 27, 2024 | The Meks Smart Social Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Meks Smart Social... |
| CVE-2024-23506 | MEDIUM | 6.5 | 0.5% | Jan 27, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in InstaWP InstaWP Connect instawp-connect.This issue af... |
| CVE-2024-0948 | MEDIUM | 6.1 | 0.5% | Jan 26, 2024 | ** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue af... |
| CVE-2024-0944 | MEDIUM | 5.3 | 1.5% | Jan 26, 2024 | A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue ... |
| CVE-2024-0943 | MEDIUM | 5.3 | 0.6% | Jan 26, 2024 | A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerab... |
| CVE-2024-0942 | MEDIUM | 4.3 | 0.7% | Jan 26, 2024 | A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected i... |
| CVE-2024-20305 | MEDIUM | 4.8 | 0.4% | Jan 26, 2024 | A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att... |
| CVE-2024-23820 | MEDIUM | 6.5 | 0.7% | Jan 26, 2024 | OpenFGA, an authorization/permission engine, is vulnerable to a denial of service attack in versions prior to 1.4.3. In ... |
| CVE-2024-22551 | MEDIUM | 6.1 | 0.4% | Jan 26, 2024 | WhatACart v2.0.7 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /site/... |
| CVE-2024-22550 | MEDIUM | 6.1 | 0.6% | Jan 26, 2024 | An arbitrary file upload vulnerability in the component /alsdemo/ss/mediam.cgi of ShopSite v14.0 allows attackers to exe... |
| CVE-2024-23896 | MEDIUM | 6.1 | 0.5% | Jan 26, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n... |
| CVE-2024-23894 | MEDIUM | 6.1 | 0.4% | Jan 26, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n... |
| CVE-2024-23893 | MEDIUM | 6.1 | 0.4% | Jan 26, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n... |
| CVE-2024-23892 | MEDIUM | 6.1 | 0.4% | Jan 26, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now