2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4662 | HIGH | 8.8 | 0.9% | May 23, 2024 | The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8... |
| CVE-2024-5232 | MEDIUM | 6.5 | 0.4% | May 23, 2024 | A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critic... |
| CVE-2024-4431 | MEDIUM | 6.4 | 0.4% | May 23, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ p... |
| CVE-2024-5231 | MEDIUM | 6.5 | 0.4% | May 23, 2024 | A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affec... |
| CVE-2024-4895 | MEDIUM | 4.7 | 0.4% | May 23, 2024 | The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor... |
| CVE-2024-5230 | MEDIUM | 6.9 | 18.8% | May 23, 2024 | A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulner... |
| CVE-2024-4978 | HIGH | 8.4 | 26.9% | May 23, 2024 | Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected... |
| CVE-2024-4783 | MEDIUM | 6.4 | 0.3% | May 23, 2024 | The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tmin... |
| CVE-2024-4486 | MEDIUM | 6.4 | 0.3% | May 23, 2024 | The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP C... |
| CVE-2024-3201 | MEDIUM | 6.4 | 0.3% | May 23, 2024 | The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' s... |
| CVE-2024-3065 | MEDIUM | 4.4 | 0.3% | May 23, 2024 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-1855 | MEDIUM | 5.3 | 0.4% | May 23, 2024 | The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPr... |
| CVE-2024-3708 | — | — | — | May 23, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-29853 | HIGH | 7.8 | 0.2% | May 22, 2024 | An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation. |
| CVE-2024-29852 | LOW | 2.7 | 0.5% | May 22, 2024 | Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs. |
| CVE-2024-29851 | HIGH | 7.2 | 0.9% | May 22, 2024 | Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account. |
| CVE-2024-29850 | HIGH | 8.8 | 0.8% | May 22, 2024 | Veeam Backup Enterprise Manager allows account takeover via NTLM relay. |
| CVE-2024-29849 | CRITICAL | 9.8 | 16.7% | May 22, 2024 | Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface. |
| CVE-2024-22026 | MEDIUM | 6.7 | 1.1% | May 22, 2024 | A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell re... |
| CVE-2024-4454 | HIGH | 7.8 | 0.4% | May 22, 2024 | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allo... |
| CVE-2024-4453 | HIGH | 7.8 | 1.6% | May 22, 2024 | GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2024-4267 | CRITICAL | 9.8 | 1.5% | May 22, 2024 | A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' mod... |
| CVE-2024-31895 | MEDIUM | 6.5 | 0.3% | May 22, 2024 | IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user informa... |
| CVE-2024-31894 | MEDIUM | 4.3 | 0.3% | May 22, 2024 | IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user informa... |
| CVE-2024-27264 | HIGH | 7.8 | 0.1% | May 22, 2024 | IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now