2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38536 | HIGH | 7.5 | 0.9% | Jul 11, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A ... |
| CVE-2024-38535 | HIGH | 7.5 | 1.2% | Jul 11, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Su... |
| CVE-2024-38534 | HIGH | 7.5 | 0.9% | Jul 11, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Cr... |
| CVE-2024-37151 | HIGH | 7.5 | 0.6% | Jul 11, 2024 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. M... |
| CVE-2024-28872 | HIGH | 8.1 | 0.3% | Jul 11, 2024 | The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it... |
| CVE-2024-6035 | MEDIUM | 6.1 | 0.4% | Jul 11, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerabil... |
| CVE-2024-6643 | — | — | — | Jul 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-6407 | HIGH | 7.5 | 0.4% | Jul 11, 2024 | CWE-200: Information Exposure vulnerability exists that could cause disclosure of credentials when a specially crafted m... |
| CVE-2024-6528 | MEDIUM | 6.1 | 0.3% | Jul 11, 2024 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c... |
| CVE-2024-5681 | HIGH | 7.8 | 0.2% | Jul 11, 2024 | CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, a... |
| CVE-2024-5680 | MEDIUM | 5.5 | 0.1% | Jul 11, 2024 | CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicio... |
| CVE-2024-5679 | HIGH | 7.1 | 0.1% | Jul 11, 2024 | CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a... |
| CVE-2024-2602 | HIGH | 7.8 | 0.3% | Jul 11, 2024 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could r... |
| CVE-2024-38433 | MEDIUM | 6.7 | 0.2% | Jul 11, 2024 | Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7... |
| CVE-2024-6666 | HIGH | 8.8 | 0.5% | Jul 11, 2024 | The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all version... |
| CVE-2024-6624 | CRITICAL | 9.8 | 2.9% | Jul 11, 2024 | The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3... |
| CVE-2024-6385 | CRITICAL | 9.8 | 6.0% | Jul 11, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 p... |
| CVE-2024-6256 | MEDIUM | 5.4 | 0.4% | Jul 11, 2024 | The Feeds for YouTube (YouTube video, channel, and gallery plugin) plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-5470 | LOW | 2.7 | 0.3% | Jul 11, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to... |
| CVE-2024-5257 | LOW | 2.7 | 0.4% | Jul 11, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to... |
| CVE-2024-2880 | LOW | 2.7 | 0.3% | Jul 11, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 p... |
| CVE-2024-6138 | MEDIUM | 4.8 | 0.4% | Jul 11, 2024 | The Secure Copy Content Protection and Content Locking WordPress plugin before 4.0.9 does not sanitise and escape some o... |
| CVE-2024-6026 | MEDIUM | 5.4 | 0.4% | Jul 11, 2024 | The Slider by 10Web WordPress plugin before 1.2.56 does not sanitise and escape some of its Slide options, which could ... |
| CVE-2024-6025 | MEDIUM | 5.4 | 0.4% | Jul 11, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.0.5 does not sanitise and escape some of its Quiz settings, ... |
| CVE-2024-5444 | MEDIUM | 5.4 | 0.3% | Jul 11, 2024 | The Bible Text WordPress plugin through 0.2 does not validate and escape some of its shortcode attributes before outputt... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now