2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4474 | MEDIUM | 4.3 | 6.0% | Jun 21, 2024 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which coul... |
| CVE-2024-4384 | MEDIUM | 4.8 | 0.4% | Jun 21, 2024 | The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-4382 | MEDIUM | 6.5 | 0.2% | Jun 21, 2024 | The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow atta... |
| CVE-2024-4381 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-4377 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before out... |
| CVE-2024-5756 | CRITICAL | 9.8 | 0.7% | Jun 21, 2024 | The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f... |
| CVE-2024-5455 | HIGH | 8.8 | 0.6% | Jun 21, 2024 | The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up... |
| CVE-2024-3961 | MEDIUM | 5.3 | 0.4% | Jun 21, 2024 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to ... |
| CVE-2024-6218 | CRITICAL | 9.8 | 0.7% | Jun 21, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. Affecte... |
| CVE-2024-6217 | HIGH | 8.8 | 0.5% | Jun 21, 2024 | A vulnerability classified as critical was found in SourceCodester Food Ordering Management System 1.0. Affected by this... |
| CVE-2024-6216 | HIGH | 8.8 | 0.5% | Jun 21, 2024 | A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. Affected is... |
| CVE-2024-6215 | HIGH | 8.8 | 0.5% | Jun 21, 2024 | A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been rated as critical. Th... |
| CVE-2024-5503 | HIGH | 8.8 | 0.8% | Jun 21, 2024 | The WP Blog Post Layouts plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including... |
| CVE-2024-5344 | MEDIUM | 6.1 | 0.3% | Jun 21, 2024 | The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2024-3610 | MEDIUM | 5.3 | 0.5% | Jun 21, 2024 | The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2024-1955 | MEDIUM | 4.3 | 0.3% | Jun 21, 2024 | The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2024-1639 | MEDIUM | 6.5 | 0.4% | Jun 21, 2024 | The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2024-6214 | HIGH | 8.8 | 0.5% | Jun 21, 2024 | A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been declared as critical. This ... |
| CVE-2024-6213 | CRITICAL | 9.8 | 0.7% | Jun 21, 2024 | A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critica... |
| CVE-2024-6212 | MEDIUM | 6.1 | 0.5% | Jun 21, 2024 | A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected... |
| CVE-2024-38361 | MEDIUM | 5.3 | 0.4% | Jun 20, 2024 | Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom... |
| CVE-2024-38359 | MEDIUM | 6.5 | 0.6% | Jun 20, 2024 | The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability i... |
| CVE-2024-37899 | HIGH | 8 | 0.7% | Jun 20, 2024 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin d... |
| CVE-2024-35246 | HIGH | 8.7 | 0.5% | Jun 20, 2024 | An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly. |
| CVE-2024-32943 | HIGH | 8.7 | 0.5% | Jun 20, 2024 | An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now