2024 CVE Vulnerabilities
39,241 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4206 | — | — | — | Jun 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-4155 | — | — | — | Jun 11, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-35716 | HIGH | 8.8 | 0.3% | Jun 11, 2024 | Missing Authorization vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic ... |
| CVE-2024-35692 | HIGH | 7.3 | 0.3% | Jun 11, 2024 | Missing Authorization vulnerability in Termly Cookie Consent.This issue affects Cookie Consent: from n/a through 3.2. |
| CVE-2024-34824 | MEDIUM | 6.3 | 0.2% | Jun 11, 2024 | Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPres... |
| CVE-2024-24704 | MEDIUM | 6.3 | 0.3% | Jun 11, 2024 | Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a th... |
| CVE-2024-5531 | MEDIUM | 6.4 | 0.3% | Jun 11, 2024 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions ... |
| CVE-2024-4266 | HIGH | 7.5 | 0.5% | Jun 11, 2024 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Sens... |
| CVE-2024-3549 | CRITICAL | 9.9 | 0.5% | Jun 11, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSort... |
| CVE-2024-4319 | MEDIUM | 5.3 | 0.5% | Jun 11, 2024 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi... |
| CVE-2024-3723 | MEDIUM | 5.3 | 0.4% | Jun 11, 2024 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t... |
| CVE-2024-31402 | MEDIUM | 4.3 | 0.3% | Jun 11, 2024 | Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete ... |
| CVE-2024-31399 | MEDIUM | 6.5 | 0.4% | Jun 11, 2024 | Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerabili... |
| CVE-2024-31398 | MEDIUM | 4.3 | 0.3% | Jun 11, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability i... |
| CVE-2024-31397 | MEDIUM | 4.9 | 0.5% | Jun 11, 2024 | Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a u... |
| CVE-2024-5530 | MEDIUM | 5.4 | 0.4% | Jun 11, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-36360 | CRITICAL | 9.8 | 1.6% | Jun 11, 2024 | OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and e... |
| CVE-2024-35329 | — | — | — | Jun 11, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-31404 | MEDIUM | 4.3 | 0.3% | Jun 11, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user w... |
| CVE-2024-31403 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter an... |
| CVE-2024-31401 | CRITICAL | 9 | 0.5% | Jun 11, 2024 | Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an admin... |
| CVE-2024-31400 | MEDIUM | 6.5 | 0.3% | Jun 11, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability i... |
| CVE-2024-29855 | CRITICAL | 9 | 21.6% | Jun 11, 2024 | Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator |
| CVE-2024-5090 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's SiteOri... |
| CVE-2024-37176 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access level... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now