2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36789 | HIGH | 8.1 | 0.4% | Jun 7, 2024 | An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to de... |
| CVE-2024-36788 | MEDIUM | 4.8 | 0.3% | Jun 7, 2024 | Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers... |
| CVE-2024-36787 | HIGH | 8.8 | 0.6% | Jun 7, 2024 | An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the admin... |
| CVE-2024-36773 | MEDIUM | 4.8 | 0.4% | Jun 7, 2024 | A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT... |
| CVE-2024-37160 | MEDIUM | 4.8 | 0.5% | Jun 7, 2024 | Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execut... |
| CVE-2024-31878 | MEDIUM | 5.3 | 0.4% | Jun 7, 2024 | IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. Thi... |
| CVE-2024-5599 | HIGH | 7.5 | 0.5% | Jun 7, 2024 | The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Expos... |
| CVE-2024-5542 | MEDIUM | 6.1 | 0.3% | Jun 7, 2024 | The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu... |
| CVE-2024-5438 | MEDIUM | 4.3 | 0.3% | Jun 7, 2024 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere... |
| CVE-2024-5382 | MEDIUM | 5.3 | 0.3% | Jun 7, 2024 | The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu... |
| CVE-2024-36673 | CRITICAL | 9.8 | 0.5% | Jun 7, 2024 | Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerabi... |
| CVE-2024-5734 | HIGH | 8.8 | 0.6% | Jun 7, 2024 | A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknow... |
| CVE-2024-5733 | CRITICAL | 9.8 | 0.6% | Jun 7, 2024 | A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects... |
| CVE-2024-4610 | HIGH | 7.8 | 0.8% | Jun 7, 2024 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-... |
| CVE-2024-5637 | HIGH | 8.1 | 0.8% | Jun 7, 2024 | The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on... |
| CVE-2024-5732 | CRITICAL | 9.8 | 0.9% | Jun 7, 2024 | A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects... |
| CVE-2024-5645 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter withi... |
| CVE-2024-5481 | HIGH | 8.8 | 0.7% | Jun 7, 2024 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all v... |
| CVE-2024-5426 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2024-4703 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_pa... |
| CVE-2024-4489 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cust... |
| CVE-2024-4488 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list... |
| CVE-2024-4451 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_vide... |
| CVE-2024-5003 | MEDIUM | 5.4 | 0.2% | Jun 7, 2024 | The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as we... |
| CVE-2024-4756 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high p... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now