2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3597 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc... |
| CVE-2024-3562 | HIGH | 8.8 | 0.6% | Jun 20, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.... |
| CVE-2024-3561 | HIGH | 8.8 | 0.5% | Jun 20, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versio... |
| CVE-2024-3558 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' p... |
| CVE-2024-1168 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social ima... |
| CVE-2024-6176 | MEDIUM | 4.8 | 0.2% | Jun 20, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanni... |
| CVE-2024-6103 | HIGH | 8.8 | 0.6% | Jun 20, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-6102 | HIGH | 8.8 | 0.7% | Jun 20, 2024 | Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially ex... |
| CVE-2024-6101 | HIGH | 8.8 | 0.8% | Jun 20, 2024 | Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of ... |
| CVE-2024-6100 | HIGH | 8.8 | 1.1% | Jun 20, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a ... |
| CVE-2024-5182 | CRITICAL | 9.1 | 25.5% | Jun 20, 2024 | A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parame... |
| CVE-2024-36684 | CRITICAL | 9.8 | 0.4% | Jun 19, 2024 | In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection.... |
| CVE-2024-36680 | HIGH | 7.5 | 10.1% | Jun 19, 2024 | In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The aj... |
| CVE-2024-36679 | CRITICAL | 10 | 0.6% | Jun 19, 2024 | In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injectio... |
| CVE-2024-36678 | CRITICAL | 9.8 | 0.6% | Jun 19, 2024 | In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL inje... |
| CVE-2024-36677 | HIGH | 7.5 | 0.4% | Jun 19, 2024 | In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct ... |
| CVE-2024-34994 | CRITICAL | 9.8 | 0.4% | Jun 19, 2024 | In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injecti... |
| CVE-2024-34990 | CRITICAL | 10 | 0.5% | Jun 19, 2024 | In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for Prest... |
| CVE-2024-33836 | CRITICAL | 9.8 | 0.5% | Jun 19, 2024 | In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload fil... |
| CVE-2024-38358 | LOW | 2.9 | 0.2% | Jun 19, 2024 | Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink ... |
| CVE-2024-38357 | MEDIUM | 6.1 | 0.5% | Jun 19, 2024 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte... |
| CVE-2024-38356 | MEDIUM | 6.1 | 0.5% | Jun 19, 2024 | TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte... |
| CVE-2024-38355 | HIGH | 7.3 | 0.7% | Jun 19, 2024 | Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket.... |
| CVE-2024-34993 | MEDIUM | 6.3 | 0.3% | Jun 19, 2024 | In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy... |
| CVE-2024-38352 | — | — | — | Jun 19, 2024 | Rejected reason: CVE was assigned in error. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now