2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4553 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-4435 | HIGH | 7.5 | 0.5% | May 21, 2024 | When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered... |
| CVE-2024-4875 | MEDIUM | 4.3 | 0.8% | May 21, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss... |
| CVE-2024-4566 | HIGH | 7.1 | 0.4% | May 21, 2024 | The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2024-3345 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortc... |
| CVE-2024-4710 | MEDIUM | 6.4 | 0.3% | May 21, 2024 | The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_m... |
| CVE-2024-4470 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-4442 | CRITICAL | 9.1 | 1.2% | May 21, 2024 | The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and includ... |
| CVE-2024-4372 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users... |
| CVE-2024-4290 | HIGH | 7.1 | 0.4% | May 21, 2024 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-4289 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting ... |
| CVE-2024-4061 | MEDIUM | 4.8 | 0.4% | May 21, 2024 | The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-2189 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget... |
| CVE-2024-4943 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in a... |
| CVE-2024-3155 | MEDIUM | 6.4 | 0.3% | May 21, 2024 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre... |
| CVE-2024-0816 | MEDIUM | 5.5 | 0.1% | May 21, 2024 | The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local a... |
| CVE-2024-5145 | HIGH | 8.8 | 0.7% | May 20, 2024 | A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue a... |
| CVE-2024-4985 | CRITICAL | 9.8 | 2.6% | May 20, 2024 | An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sig... |
| CVE-2024-34710 | HIGH | 7.1 | 0.4% | May 20, 2024 | Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to ... |
| CVE-2024-35195 | MEDIUM | 5.6 | 0.3% | May 20, 2024 | Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is ... |
| CVE-2024-35194 | MEDIUM | 5.3 | 0.4% | May 20, 2024 | Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial o... |
| CVE-2024-35192 | MEDIUM | 5.5 | 0.2% | May 20, 2024 | Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images fro... |
| CVE-2024-35191 | MEDIUM | 4.4 | 0.3% | May 20, 2024 | Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include mali... |
| CVE-2024-33901 | MEDIUM | 6.5 | 0.7% | May 20, 2024 | Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in t... |
| CVE-2024-33900 | MEDIUM | 6.5 | 0.3% | May 20, 2024 | KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now