2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21630 | MEDIUM | 4.3 | 0.4% | Jan 25, 2024 | Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applie... |
| CVE-2024-22432 | MEDIUM | 6.5 | 0.1% | Jan 25, 2024 | Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup dura... |
| CVE-2024-0879 | MEDIUM | 4.3 | 0.4% | Jan 25, 2024 | Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is ... |
| CVE-2024-23855 | MEDIUM | 6.1 | 0.4% | Jan 25, 2024 | A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are n... |
| CVE-2024-22099 | MEDIUM | 5.5 | 0.6% | Jan 25, 2024 | NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows O... |
| CVE-2024-0625 | MEDIUM | 4.8 | 0.4% | Jan 25, 2024 | The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notifica... |
| CVE-2024-0688 | MEDIUM | 4.8 | 0.3% | Jan 25, 2024 | The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings i... |
| CVE-2024-0624 | MEDIUM | 5.3 | 1.0% | Jan 25, 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab... |
| CVE-2024-0617 | MEDIUM | 5.3 | 0.5% | Jan 25, 2024 | The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-23905 | MEDIUM | 5.4 | 0.6% | Jan 24, 2024 | Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protecti... |
| CVE-2024-23903 | MEDIUM | 5.3 | 0.5% | Jan 24, 2024 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when ch... |
| CVE-2024-23902 | MEDIUM | 4.3 | 0.3% | Jan 24, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier... |
| CVE-2024-23901 | MEDIUM | 6.5 | 0.5% | Jan 24, 2024 | Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared w... |
| CVE-2024-23900 | MEDIUM | 4.3 | 0.7% | Jan 24, 2024 | Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configur... |
| CVE-2024-23899 | MEDIUM | 6.5 | 1.3% | Jan 24, 2024 | Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replace... |
| CVE-2024-23649 | MEDIUM | 6.5 | 0.5% | Jan 24, 2024 | Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users ca... |
| CVE-2024-22720 | MEDIUM | 4.8 | 0.4% | Jan 24, 2024 | Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature. |
| CVE-2024-22229 | MEDIUM | 4.3 | 0.3% | Jan 24, 2024 | Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated atta... |
| CVE-2024-22725 | MEDIUM | 6.1 | 0.4% | Jan 24, 2024 | Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability w... |
| CVE-2024-22308 | MEDIUM | 6.1 | 0.3% | Jan 24, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affec... |
| CVE-2024-22134 | MEDIUM | 6.5 | 0.3% | Jan 24, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affe... |
| CVE-2024-0854 | MEDIUM | 5.4 | 0.4% | Jan 24, 2024 | URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manag... |
| CVE-2024-0665 | MEDIUM | 6.1 | 0.5% | Jan 24, 2024 | The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all... |
| CVE-2024-22372 | MEDIUM | 6.8 | 0.8% | Jan 24, 2024 | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrat... |
| CVE-2024-22366 | MEDIUM | 6.8 | 0.3% | Jan 24, 2024 | Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now