2024 CVE Vulnerabilities
39,242 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-27776 | CRITICAL | 9.8 | 0.6% | Jun 2, 2024 | MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow ... |
| CVE-2024-2178 | HIGH | 7.5 | 0.6% | Jun 2, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' en... |
| CVE-2024-5587 | MEDIUM | 6.9 | 0.5% | Jun 2, 2024 | A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown functi... |
| CVE-2024-4344 | MEDIUM | 4.3 | 0.2% | Jun 2, 2024 | The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Sit... |
| CVE-2024-35647 | MEDIUM | 5.9 | 0.3% | Jun 2, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Noti... |
| CVE-2024-35646 | MEDIUM | 5.9 | 0.3% | Jun 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnens... |
| CVE-2024-35645 | MEDIUM | 5.9 | 0.3% | Jun 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar R... |
| CVE-2024-4148 | HIGH | 7.5 | 0.6% | Jun 1, 2024 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10.... |
| CVE-2024-5348 | HIGH | 8.8 | 0.8% | Jun 1, 2024 | The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi... |
| CVE-2024-3821 | HIGH | 7.3 | 0.3% | Jun 1, 2024 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unau... |
| CVE-2024-3820 | CRITICAL | 10 | 0.7% | Jun 1, 2024 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL ... |
| CVE-2024-3200 | MEDIUM | 6.5 | 0.5% | Jun 1, 2024 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode ... |
| CVE-2024-35636 | MEDIUM | 4.3 | 0.2% | Jun 1, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uplo... |
| CVE-2024-4958 | HIGH | 7.1 | 0.3% | Jun 1, 2024 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ... |
| CVE-2024-2295 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-for... |
| CVE-2024-2506 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St... |
| CVE-2024-1324 | MEDIUM | 5.3 | 0.3% | Jun 1, 2024 | The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili... |
| CVE-2024-5501 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-4342 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-4087 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-3565 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-3564 | HIGH | 8.8 | 0.6% | Jun 1, 2024 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to... |
| CVE-2024-4711 | MEDIUM | 5.4 | 0.4% | Jun 1, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-2933 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the S... |
| CVE-2024-5138 | HIGH | 8.1 | 0.8% | May 31, 2024 | The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now