2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5858 | MEDIUM | 4.3 | 0.3% | Jun 15, 2024 | The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-4551 | HIGH | 8.8 | 0.6% | Jun 15, 2024 | The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi... |
| CVE-2024-4258 | CRITICAL | 9.8 | 0.8% | Jun 15, 2024 | The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi... |
| CVE-2024-4095 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'ex... |
| CVE-2024-3105 | CRITICAL | 9.9 | 2.8% | Jun 15, 2024 | The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execu... |
| CVE-2024-2695 | MEDIUM | 5.4 | 0.3% | Jun 15, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco... |
| CVE-2024-1399 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-6000 | HIGH | 7.1 | 0.5% | Jun 15, 2024 | The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp... |
| CVE-2024-5871 | CRITICAL | 9.8 | 0.7% | Jun 15, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc... |
| CVE-2024-5868 | MEDIUM | 5.3 | 0.3% | Jun 15, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and inclu... |
| CVE-2024-5263 | MEDIUM | 5.4 | 0.3% | Jun 15, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and T... |
| CVE-2024-4479 | MEDIUM | 5.4 | 0.4% | Jun 15, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_en... |
| CVE-2024-3815 | MEDIUM | 4.8 | 0.3% | Jun 15, 2024 | The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page i... |
| CVE-2024-3814 | MEDIUM | 4.8 | 0.3% | Jun 15, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module i... |
| CVE-2024-3813 | HIGH | 8.8 | 0.7% | Jun 15, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8... |
| CVE-2024-2544 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss... |
| CVE-2024-6003 | HIGH | 7.3 | 0.5% | Jun 14, 2024 | A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been clas... |
| CVE-2024-30120 | LOW | 2.9 | 0.2% | Jun 14, 2024 | HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application. |
| CVE-2024-30119 | LOW | 3.7 | 0.2% | Jun 14, 2024 | HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacke... |
| CVE-2024-21988 | MEDIUM | 5.3 | 0.2% | Jun 14, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of se... |
| CVE-2024-2875 | — | — | — | Jun 14, 2024 | Rejected reason: ** REJECT ** Duplicate reservation. Please use CVE-2024-4258 instead. |
| CVE-2024-37889 | MEDIUM | 6.5 | 1.0% | Jun 14, 2024 | MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while sign... |
| CVE-2024-37831 | CRITICAL | 9.8 | 0.4% | Jun 14, 2024 | Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter. |
| CVE-2024-36600 | HIGH | 8.4 | 0.4% | Jun 14, 2024 | Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a craft... |
| CVE-2024-37888 | MEDIUM | 6.1 | 0.9% | Jun 14, 2024 | The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerabili... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now