2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5553 | MEDIUM | 5.4 | 0.4% | Jun 12, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several... |
| CVE-2024-4564 | MEDIUM | 6.4 | 0.4% | Jun 12, 2024 | The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress... |
| CVE-2024-36856 | HIGH | 7.5 | 0.5% | Jun 12, 2024 | RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can... |
| CVE-2024-5543 | HIGH | 8.1 | 0.5% | Jun 12, 2024 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all ve... |
| CVE-2024-4892 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in ver... |
| CVE-2024-4315 | CRITICAL | 9.1 | 1.0% | Jun 12, 2024 | parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. T... |
| CVE-2024-36103 | MEDIUM | 6.8 | 0.7% | Jun 12, 2024 | OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a... |
| CVE-2024-35225 | MEDIUM | 6.1 | 0.4% | Jun 11, 2024 | Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authen... |
| CVE-2024-5847 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-5846 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap c... |
| CVE-2024-5845 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap co... |
| CVE-2024-5844 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of... |
| CVE-2024-5843 | MEDIUM | 6.5 | 0.5% | Jun 11, 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate... |
| CVE-2024-5842 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to e... |
| CVE-2024-5841 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2024-5840 | MEDIUM | 6.5 | 0.4% | Jun 11, 2024 | Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access c... |
| CVE-2024-5839 | MEDIUM | 6.5 | 0.5% | Jun 11, 2024 | Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to po... |
| CVE-2024-5838 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory a... |
| CVE-2024-5837 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bou... |
| CVE-2024-5836 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a use... |
| CVE-2024-5835 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a use... |
| CVE-2024-5834 | HIGH | 8.8 | 0.6% | Jun 11, 2024 | Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitr... |
| CVE-2024-5833 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bou... |
| CVE-2024-5832 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-5831 | HIGH | 8.8 | 0.5% | Jun 11, 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap cor... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now