2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5484 | — | — | — | May 31, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-22338 | MEDIUM | 5.5 | 0.2% | May 31, 2024 | IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to... |
| CVE-2024-5347 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribu... |
| CVE-2024-5041 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-... |
| CVE-2024-4160 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packag... |
| CVE-2024-23692 | CRITICAL | 9.8 | 99.5% | May 31, 2024 | Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vu... |
| CVE-2024-5436 | CRITICAL | 9.8 | 0.5% | May 31, 2024 | Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. ... |
| CVE-2024-5525 | HIGH | 8.8 | 0.4% | May 31, 2024 | Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a loca... |
| CVE-2024-5524 | MEDIUM | 5.3 | 0.3% | May 31, 2024 | Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered us... |
| CVE-2024-5523 | HIGH | 8.8 | 0.4% | May 31, 2024 | SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated ... |
| CVE-2024-5427 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is v... |
| CVE-2024-4469 | HIGH | 7.5 | 0.6% | May 31, 2024 | The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role... |
| CVE-2024-4379 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Glob... |
| CVE-2024-4376 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fanc... |
| CVE-2024-4205 | MEDIUM | 4.3 | 0.3% | May 31, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa... |
| CVE-2024-36246 | CRITICAL | 9.8 | 0.5% | May 31, 2024 | Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co... |
| CVE-2024-23847 | MEDIUM | 5.9 | 0.2% | May 31, 2024 | Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co... |
| CVE-2024-2793 | HIGH | 7.2 | 0.5% | May 31, 2024 | The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2024-37032 | HIGH | 8.8 | 89.6% | May 31, 2024 | Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,... |
| CVE-2024-5418 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribu... |
| CVE-2024-5345 | HIGH | 8.8 | 0.7% | May 31, 2024 | The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up ... |
| CVE-2024-32850 | CRITICAL | 9.8 | 1.2% | May 31, 2024 | Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 ... |
| CVE-2024-37018 | CRITICAL | 9.1 | 0.4% | May 31, 2024 | The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the ... |
| CVE-2024-37017 | HIGH | 8.1 | 0.5% | May 31, 2024 | asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_Time... |
| CVE-2024-5499 | HIGH | 8.8 | 0.9% | May 30, 2024 | Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitra... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now