CVEs from 2024

6,627 normalized CVEs published or assigned in this year.

Total
6,627
critical
critical 166
high
high 1,065
medium
medium 2,077
low
low 49
% Critical
2.5%
% with KEV
2.5%
% with exploit
3.4%

Top vendors

Top products

  • surveillance_station 12
  • checkmk 10
  • profilegrid 8
  • office 8
  • office_long_term_servicing_channel 6
  • propertyhive 5
  • glibc 5
  • element_pack 5
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-27966 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz And Survey Master allows Stored XSS.This issue affects Quiz And Survey Master: f…
CVE-2024-31344 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative Studio Easy Login Styler – White Label Admin Login Page for WordPress allows Sto…
CVE-2024-31102 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scimone Ignazio Prenotazioni allows Stored XSS.This issue affects Prenotazioni: from n/a through …
CVE-2024-31089 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Techblissonline.Com (Rajesh) Platinum SEO allows Stored XSS.This issue affects Platinum SEO: from…
CVE-2024-30554 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wouter Dijkstra DD Rating allows Stored XSS.This issue affects DD Rating: from n/a through 1.7.1.
CVE-2024-30553 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joby Joseph WP Twitter Mega Fan Box Widget allows Stored XSS.This issue affects WP Twitter Mega F…
CVE-2024-30548 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan underConstruction allows Stored XSS.This issue affects underConstruction: from n/a thr…
CVE-2024-30440 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Themify Event Post allows Stored XSS.This issue affects Themify Event Post: from n/a thro…
CVE-2024-30434 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-CRM System allows Stored XSS.This issue affects WP-CRM System: from n/a through 3.2.9.
CVE-2024-30452 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PluginOps Landing Page Builder allows Stored XSS.This issue affects Landing Page Builder: from n/…
CVE-2024-30448 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Supsystic Slider by Supsystic allows Stored XSS.This issue affects Slider by Supsystic: from n/a …
CVE-2024-30444 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zionbuilder.Io WordPress Page Builder – Zion Builder allows Stored XSS.This issue affects WordPre…
CVE-2024-29768 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra allows Stored XSS.This issue affects Astra: from n/a through 4.6.4.
CVE-2024-30181 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Plainware Locatoraid Store Locator allows Stored XSS.This issue affects Locatoraid Store Locator:…
CVE-2024-29818 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker allows Stored XSS.This issue affects WP…
CVE-2024-29816 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in htdat Woo Viet allows Stored XSS.This issue affects Woo Viet: from n/a through 1.5.2.
CVE-2024-29815 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aminur Islam WP Change Email Sender allows Stored XSS.This issue affects WP Change Email Sender: …
CVE-2024-29813 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CartFlows Inc. Funnel Builder by CartFlows allows Stored XSS.This issue affects Funnel Builder by…
CVE-2024-29819 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar…
CVE-2024-29929 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WC Lovers WCFM – Frontend Manager for WooCommerce allows Stored XSS.This issue affects WCFM – Fro…
CVE-2024-29922 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Quantum Cloud Slider Hero allows Stored XSS.This issue affects Slider Hero: from n/a through 8.6.…
CVE-2024-2579 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.0.16.
CVE-2024-29105 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Timersys WP Popups allows Stored XSS.This issue affects WP Popups: from n/a through 2.1.5.5.
CVE-2024-29124 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Access Manager allows Stored XSS.This issue affects Advanced Access Manager: from n/…
CVE-2024-29140 medium 5.9 5.9 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Manning MJM Clinic allows Stored XSS.This issue affects MJM Clinic: from n/a through 1.1.22.
CVE-2024-35910 medium 5.8 5.8 2y ago In the Linux kernel, the following vulnerability has been resolved: tcp: properly terminate timers for kernel sockets We had various syzbot reports about tcp timers firing after the corresponding n…
CVE-2024-32587 medium 5.8 5.8 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvialoSimple EnvíaloSimple allows Reflected XSS.This issue affects EnvíaloSimple: from n/a throu…
CVE-2024-32547 medium 5.8 5.8 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Max Bond Code Insert Manager (Q2W3 Inc Manager) allows Reflected XSS.This issue affects Code Inse…
CVE-2024-31122 medium 5.8 5.8 2y ago Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism IT Systems User Rights Access Manager allows Reflected XSS.This issue affects User Rights A…
CVE-2024-36894 medium 5.6 5.6 2y ago In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete FFS based applications can utilize the aio_cancel() cal…
CVE-2024-33655 medium 5.5 17d ago Moderate: unbound security update
CVE-2024-51394 medium 5.5 5.5 22d ago Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_MSP::loop, AP_MSP, AP_MSP.cpp c…
CVE-2024-26766 medium 5.5 4mo ago In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix sdma.h tx->num_descs off-by-one error Unfortunately the commit `fd8958efe877` introduced another error causing the `…
CVE-2024-53090 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-54456 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53241 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53135 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53229 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56645 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53119 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53216 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53170 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53680 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58088 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58075 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58083 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56603 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56662 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58068 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-50060 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-50294 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57981 medium 5.5 5.5 7mo ago Moderate: kernel security update
CVE-2024-57988 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57986 medium 5.5 5.5 7mo ago Moderate: kernel security update
CVE-2024-56709 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-53052 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-49570 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57990 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57987 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57989 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56786 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56675 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56690 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-56739 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-49864 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-46689 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-47679 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-47727 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57998 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57995 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-52332 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58077 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58057 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-57993 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58062 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58015 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-58012 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-45777 medium 5.5 7mo ago Moderate: grub2 security update
CVE-2024-50195 medium 5.5 7mo ago Moderate: kernel security update
CVE-2024-13176 medium 5.5 9mo ago Moderate: mysql:8.4 security update
CVE-2024-36357 medium 5.5 9mo ago Moderate: kernel security update
CVE-2024-47252 medium 5.5 9mo ago Insufficient escaping of user-supplied data in mod_ssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations. …
CVE-2024-36350 medium 5.5 10mo ago Moderate: kernel security update
CVE-2024-47081 medium 5.5 10mo ago RHSA-2025:14999: resource-agents security update (Moderate)
CVE-2024-57980 medium 5.5 10mo ago Moderate: kernel security update
CVE-2024-52615 medium 5.5 11mo ago Moderate: avahi security update
CVE-2024-13175 medium 5.5 5.5 11mo ago Authorization Bypass Through User-Controlled Key vulnerability in Vidco Software VOC TESTER allows Forceful Browsing. This issue affects VOC TESTER: before 12.41.0.
CVE-2024-50379 medium 5.5 11mo ago Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (…
CVE-2024-23337 medium 5.5 11mo ago jq is a command-line JSON processor. In versions up to and including 1.7.1, an integer overflow arises when assigning value using an index of 2147483647, the signed integer limit. This causes a denia…
CVE-2024-54661 medium 5.5 11mo ago readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file.
CVE-2024-53064 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: idpf: fix idpf_vc_core_init error path In an event where the platform running the device control plane is rebooted, reset is dete…
CVE-2024-45332 medium 5.5 1y ago RHSA-2025:10991: microcode_ctl security update (Moderate)
CVE-2024-43420 medium 5.5 1y ago RHSA-2025:10991: microcode_ctl security update (Moderate)
CVE-2024-53161 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: EDAC/bluefield: Fix potential integer overflow The 64-bit argument for the "get DIMM info" SMC call consists of mem_ctrl_idx left…
CVE-2024-53174 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: SUNRPC: make sure cache entry active before cache_show The function `c_show` was called with protection from RCU. This only ensur…
CVE-2024-46783 medium 5.5 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: tcp_bpf: fix return value of tcp_bpf_sendmsg() When we cork messages in psock->cork, the last message triggers the flushing will …
CVE-2024-56570 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: ovl: Filter invalid inodes with missing lookup function Add a check to the ovl_dentry_weird() function to prevent the processing …
CVE-2024-46786 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: fscache: delete fscache_cookie_lru_timer when fscache exits to avoid UAF The fscache_cookie_lru_timer is initialized when the fsc…
CVE-2024-49974 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: NFSD: Limit the number of concurrent async COPY operations Nothing appears to limit the number of concurrent async COPY operation…
CVE-2024-50107 medium 5.5 1y ago In the Linux kernel, the following vulnerability has been resolved: platform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid addresses Commit 50c6dbdfd16e ("x86/ioremap: Improve iounm…