2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5036 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-28147 | HIGH | 7.4 | 0.8% | Jun 20, 2024 | An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may ... |
| CVE-2024-34693 | MEDIUM | 5.3 | 1.6% | Jun 20, 2024 | Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB con... |
| CVE-2024-29013 | MEDIUM | 6.5 | 0.6% | Jun 20, 2024 | Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial ... |
| CVE-2024-29012 | HIGH | 7.5 | 0.5% | Jun 20, 2024 | Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause De... |
| CVE-2024-38620 | MEDIUM | 5.5 | 0.3% | Jun 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS... |
| CVE-2024-4098 | CRITICAL | 9.8 | 1.0% | Jun 20, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 ... |
| CVE-2024-38619 | MEDIUM | 5.5 | 0.3% | Jun 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is ini... |
| CVE-2024-6113 | CRITICAL | 9.8 | 0.7% | Jun 20, 2024 | A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critic... |
| CVE-2024-5522 | MEDIUM | 6.5 | 2.6% | Jun 20, 2024 | The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before... |
| CVE-2024-5475 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes b... |
| CVE-2024-4565 | MEDIUM | 6.5 | 0.4% | Jun 20, 2024 | The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 all... |
| CVE-2024-5686 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-5605 | HIGH | 8.8 | 0.6% | Jun 20, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter wit... |
| CVE-2024-4390 | MEDIUM | 6.5 | 0.5% | Jun 20, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi... |
| CVE-2024-5213 | MEDIUM | 6.5 | 0.5% | Jun 20, 2024 | In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a u... |
| CVE-2024-6179 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics Sup... |
| CVE-2024-6178 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics Sup... |
| CVE-2024-6177 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electron... |
| CVE-2024-5432 | CRITICAL | 9.8 | 0.7% | Jun 20, 2024 | The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2.... |
| CVE-2024-4742 | MEDIUM | 6.5 | 0.5% | Jun 20, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-4626 | MEDIUM | 5.4 | 0.3% | Jun 20, 2024 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and... |
| CVE-2024-3627 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2024-3605 | CRITICAL | 9.8 | 4.2% | Jun 20, 2024 | The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/r... |
| CVE-2024-3602 | MEDIUM | 4.3 | 0.3% | Jun 20, 2024 | The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPre... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now