2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-30283 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that co... |
| CVE-2024-4838 | HIGH | 7.5 | 0.6% | May 16, 2024 | The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 ... |
| CVE-2024-4634 | MEDIUM | 5.4 | 0.4% | May 16, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg... |
| CVE-2024-4617 | MEDIUM | 6.4 | 0.4% | May 16, 2024 | The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ ... |
| CVE-2024-4400 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-4385 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up ... |
| CVE-2024-4288 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto... |
| CVE-2024-35302 | MEDIUM | 6.1 | 0.3% | May 16, 2024 | In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible |
| CVE-2024-35301 | MEDIUM | 5.5 | 0.3% | May 16, 2024 | In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token |
| CVE-2024-35300 | MEDIUM | 6.1 | 0.3% | May 16, 2024 | In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible |
| CVE-2024-35299 | HIGH | 7.5 | 0.3% | May 16, 2024 | In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation |
| CVE-2024-4975 | MEDIUM | 6.1 | 0.5% | May 16, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue... |
| CVE-2024-4974 | MEDIUM | 6.1 | 0.5% | May 16, 2024 | A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an ... |
| CVE-2024-4973 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unk... |
| CVE-2024-4352 | HIGH | 8.8 | 1.2% | May 16, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data ... |
| CVE-2024-4351 | HIGH | 8.8 | 1.0% | May 16, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data ... |
| CVE-2024-4222 | HIGH | 8.2 | 0.3% | May 16, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data ... |
| CVE-2024-4972 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown p... |
| CVE-2024-4968 | MEDIUM | 6.1 | 0.5% | May 16, 2024 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected ... |
| CVE-2024-4967 | CRITICAL | 9.8 | 0.6% | May 16, 2024 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected ... |
| CVE-2024-4642 | — | — | — | May 16, 2024 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2024-4391 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event ... |
| CVE-2024-4326 | CRITICAL | 9.8 | 1.0% | May 16, 2024 | A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulne... |
| CVE-2024-4322 | HIGH | 7.5 | 30.8% | May 16, 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personali... |
| CVE-2024-4321 | HIGH | 7.5 | 0.6% | May 16, 2024 | A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now