2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5088 | MEDIUM | 5.4 | 0.4% | May 18, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter... |
| CVE-2024-4432 | MEDIUM | 6.4 | 0.3% | May 18, 2024 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg... |
| CVE-2024-3658 | — | — | — | May 18, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-51478. Reason: This candidate is a ... |
| CVE-2024-4709 | MEDIUM | 6.4 | 0.4% | May 18, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-4698 | MEDIUM | 6.4 | 0.4% | May 18, 2024 | The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_l... |
| CVE-2024-2782 | HIGH | 7.5 | 1.2% | May 18, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-2772 | MEDIUM | 5.4 | 0.3% | May 18, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-2771 | CRITICAL | 9.8 | 2.3% | May 18, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-4849 | MEDIUM | 6.4 | 0.3% | May 18, 2024 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ para... |
| CVE-2024-3812 | HIGH | 7.5 | 0.6% | May 18, 2024 | The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 ... |
| CVE-2024-3811 | MEDIUM | 6.4 | 0.3% | May 18, 2024 | The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortco... |
| CVE-2024-3810 | HIGH | 8.8 | 0.6% | May 18, 2024 | The Salient Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ... |
| CVE-2024-4891 | MEDIUM | 5.4 | 0.5% | May 18, 2024 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-4374 | MEDIUM | 5.4 | 0.4% | May 18, 2024 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets ... |
| CVE-2024-3714 | MEDIUM | 5.4 | 0.3% | May 18, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-4865 | MEDIUM | 5.4 | 0.4% | May 18, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter... |
| CVE-2024-4264 | CRITICAL | 9.8 | 0.9% | May 18, 2024 | A remote code execution (RCE) vulnerability exists in the berriai/litellm project due to improper control of the generat... |
| CVE-2024-23556 | HIGH | 7.5 | 0.4% | May 18, 2024 | SSL/TLS Renegotiation functionality potentially leading to DoS attack vulnerability. |
| CVE-2024-23554 | HIGH | 8.8 | 0.3% | May 18, 2024 | Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (R... |
| CVE-2024-23583 | MEDIUM | 6.7 | 0.2% | May 17, 2024 | An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client D... |
| CVE-2024-35313 | HIGH | 7.3 | 0.3% | May 17, 2024 | In Tor Arti before 1.2.3, circuits sometimes incorrectly have a length of 3 (with full vanguards), aka TROVE-2024-004. |
| CVE-2024-35312 | MEDIUM | 6.2 | 0.2% | May 17, 2024 | In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003. |
| CVE-2024-25742 | MEDIUM | 6.5 | 0.2% | May 17, 2024 | In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and c... |
| CVE-2024-5069 | CRITICAL | 9.8 | 0.6% | May 17, 2024 | A vulnerability, which was classified as critical, has been found in SourceCodester Simple Online Mens Salon Management ... |
| CVE-2024-5066 | HIGH | 8.8 | 0.6% | May 17, 2024 | A vulnerability classified as critical was found in PHPGurukul Online Course Registration System 3.1. Affected by this v... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now