2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-20876 | HIGH | 7.8 | 0.1% | Jun 4, 2024 | Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to mem... |
| CVE-2024-20875 | MEDIUM | 5.5 | 0.1% | Jun 4, 2024 | Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to ac... |
| CVE-2024-20874 | HIGH | 7.8 | 0.2% | Jun 4, 2024 | Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch... |
| CVE-2024-20873 | MEDIUM | 6 | 0.1% | Jun 4, 2024 | Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attack... |
| CVE-2024-4997 | MEDIUM | 5.3 | 0.4% | Jun 4, 2024 | The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links... |
| CVE-2024-4857 | MEDIUM | 6.1 | 0.4% | Jun 4, 2024 | The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could al... |
| CVE-2024-4856 | HIGH | 8.2 | 0.5% | Jun 4, 2024 | The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back... |
| CVE-2024-4750 | MEDIUM | 5.3 | 0.4% | Jun 4, 2024 | The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private... |
| CVE-2024-4749 | HIGH | 8.3 | 0.4% | Jun 4, 2024 | The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it ... |
| CVE-2024-4697 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’... |
| CVE-2024-4462 | MEDIUM | 4.4 | 0.3% | Jun 4, 2024 | The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2024-4274 | MEDIUM | 4.3 | 0.5% | Jun 4, 2024 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation... |
| CVE-2024-4273 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_proper... |
| CVE-2024-4180 | CRITICAL | 9.1 | 1.8% | Jun 4, 2024 | The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering som... |
| CVE-2024-4057 | MEDIUM | 6.1 | 0.4% | Jun 4, 2024 | The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its bloc... |
| CVE-2024-3555 | HIGH | 7.2 | 0.3% | Jun 4, 2024 | The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to un... |
| CVE-2024-3230 | MEDIUM | 6.4 | 0.3% | Jun 4, 2024 | The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-at... |
| CVE-2024-3031 | MEDIUM | 4.4 | 0.3% | Jun 4, 2024 | The Fluid Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2024-2470 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-2382 | MEDIUM | 5.3 | 0.2% | Jun 4, 2024 | The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions u... |
| CVE-2024-2019 | HIGH | 7.5 | 0.4% | Jun 4, 2024 | The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss... |
| CVE-2024-1718 | MEDIUM | 5.3 | 0.2% | Jun 4, 2024 | The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ... |
| CVE-2024-1717 | MEDIUM | 4.3 | 0.4% | Jun 4, 2024 | The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2024-0757 | MEDIUM | 5.4 | 0.9% | Jun 4, 2024 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file e... |
| CVE-2024-3888 | MEDIUM | 6.4 | 0.3% | Jun 4, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now