2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37124 | CRITICAL | 9.8 | 0.5% | Jun 19, 2024 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited,... |
| CVE-2024-36978 | HIGH | 7.8 | 0.3% | Jun 19, 2024 | In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in m... |
| CVE-2024-36480 | CRITICAL | 9.8 | 0.4% | Jun 19, 2024 | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability... |
| CVE-2024-36252 | MEDIUM | 6.3 | 0.2% | Jun 19, 2024 | Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.... |
| CVE-2024-1407 | MEDIUM | 5.4 | 0.2% | Jun 19, 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab... |
| CVE-2024-6132 | HIGH | 8.8 | 1.4% | Jun 19, 2024 | The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali... |
| CVE-2024-5853 | HIGH | 8.8 | 0.8% | Jun 19, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2024-5574 | HIGH | 7.5 | 0.8% | Jun 19, 2024 | The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu... |
| CVE-2024-5343 | HIGH | 8.8 | 0.3% | Jun 19, 2024 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery ... |
| CVE-2024-5208 | MEDIUM | 6.5 | 0.6% | Jun 19, 2024 | An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. T... |
| CVE-2024-3229 | CRITICAL | 9.8 | 0.9% | Jun 19, 2024 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2024-35298 | MEDIUM | 4.3 | 0.3% | Jun 19, 2024 | Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 all... |
| CVE-2024-5768 | MEDIUM | 6.4 | 0.2% | Jun 19, 2024 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2024-5724 | HIGH | 8.8 | 0.6% | Jun 19, 2024 | The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc... |
| CVE-2024-5649 | HIGH | 8.8 | 0.4% | Jun 19, 2024 | The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.... |
| CVE-2024-5021 | CRITICAL | 9.3 | 0.4% | Jun 19, 2024 | The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in a... |
| CVE-2024-4873 | MEDIUM | 4.3 | 0.3% | Jun 19, 2024 | The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl... |
| CVE-2024-4787 | MEDIUM | 5.8 | 0.3% | Jun 19, 2024 | The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, ... |
| CVE-2024-4663 | MEDIUM | 6.4 | 0.4% | Jun 19, 2024 | The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ param... |
| CVE-2024-4623 | MEDIUM | 6.4 | 0.3% | Jun 19, 2024 | The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p... |
| CVE-2024-4541 | MEDIUM | 4.3 | 0.2% | Jun 19, 2024 | The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2024-4450 | MEDIUM | 6.3 | 0.3% | Jun 19, 2024 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing... |
| CVE-2024-3984 | MEDIUM | 6.4 | 0.3% | Jun 19, 2024 | The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-2381 | HIGH | 8.8 | 0.9% | Jun 19, 2024 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missin... |
| CVE-2024-6125 | HIGH | 8.1 | 0.5% | Jun 19, 2024 | The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and in... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now