2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5289 | MEDIUM | 5.4 | 0.3% | Jun 27, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-6323 | HIGH | 7.5 | 0.5% | Jun 27, 2024 | Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior t... |
| CVE-2024-5655 | HIGH | 8.8 | 7.5% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-5430 | MEDIUM | 4.9 | 0.5% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 ... |
| CVE-2024-4901 | MEDIUM | 5.4 | 32.8% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-4557 | MEDIUM | 6.5 | 0.5% | Jun 27, 2024 | Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0... |
| CVE-2024-4011 | MEDIUM | 4.3 | 0.3% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-3959 | MEDIUM | 6.5 | 0.4% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-3115 | MEDIUM | 4.3 | 0.3% | Jun 27, 2024 | An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 16.11.5, starting from 17.0 prio... |
| CVE-2024-2191 | MEDIUM | 5.3 | 0.4% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-1816 | MEDIUM | 5.5 | 0.3% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 12.0 prior to 16.11.5, starting from 17.0 p... |
| CVE-2024-1493 | MEDIUM | 6.5 | 0.5% | Jun 27, 2024 | An issue was discovered in GitLab CE/EE affecting all versions starting from 9.2 prior to 16.11.5, starting from 17.0 pr... |
| CVE-2024-28984 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malici... |
| CVE-2024-28983 | MEDIUM | 6.1 | 0.3% | Jun 26, 2024 | Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malici... |
| CVE-2024-28982 | HIGH | 8.2 | 0.4% | Jun 26, 2024 | Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly... |
| CVE-2024-37734 | CRITICAL | 9.8 | 0.8% | Jun 26, 2024 | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid par... |
| CVE-2024-37571 | MEDIUM | 4.3 | 0.4% | Jun 26, 2024 | Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensiti... |
| CVE-2024-37248 | MEDIUM | 6.5 | 0.3% | Jun 26, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreat... |
| CVE-2024-37247 | MEDIUM | 6.5 | 0.2% | Jun 26, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in twinpicture... |
| CVE-2024-6355 | MEDIUM | 6.9 | 0.4% | Jun 26, 2024 | A vulnerability was found in Genexis Tilgin Fiber Home Gateway HG1522 CSx000-01_09_01_12. It has been declared as proble... |
| CVE-2024-36829 | HIGH | 7.5 | 0.4% | Jun 26, 2024 | Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted que... |
| CVE-2024-23767 | HIGH | 8.8 | 0.4% | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated ch... |
| CVE-2024-23766 | HIGH | 7.5 | 0.4% | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An u... |
| CVE-2024-23765 | MEDIUM | 4 | 0.2% | Jun 26, 2024 | An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes an unidentified service on port ... |
| CVE-2024-1839 | CRITICAL | 10 | 0.5% | Jun 26, 2024 | Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now