2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4208 | MEDIUM | 5.4 | 0.3% | May 15, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-3189 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-32888 | CRITICAL | 10 | 0.8% | May 15, 2024 | The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDB... |
| CVE-2024-4847 | HIGH | 8.8 | 0.6% | May 15, 2024 | The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to ... |
| CVE-2024-4734 | MEDIUM | 4.4 | 0.3% | May 15, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin se... |
| CVE-2024-4656 | MEDIUM | 4.4 | 0.3% | May 15, 2024 | The Import and export users and customers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user... |
| CVE-2024-4618 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Team Member... |
| CVE-2024-4373 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-4199 | MEDIUM | 4.3 | 0.3% | May 15, 2024 | The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to unauthorized access of functionality due to a... |
| CVE-2024-35109 | MEDIUM | 6.5 | 0.2% | May 15, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /homePro_deal.php?mudi=add&... |
| CVE-2024-35108 | HIGH | 8.8 | 0.3% | May 15, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mud... |
| CVE-2024-3744 | MEDIUM | 6.5 | 0.3% | May 15, 2024 | A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe ser... |
| CVE-2024-4370 | MEDIUM | 5.4 | 0.4% | May 15, 2024 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-4363 | MEDIUM | 6.4 | 0.4% | May 15, 2024 | The Visual Portfolio, Photo Gallery & Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... |
| CVE-2024-0437 | MEDIUM | 4.3 | 0.4% | May 15, 2024 | The Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease plugin for WordPress is vu... |
| CVE-2024-4666 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t... |
| CVE-2024-31483 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol... |
| CVE-2024-31482 | HIGH | 7.5 | 0.5% | May 14, 2024 | An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI pr... |
| CVE-2024-31481 | HIGH | 7.5 | 0.6% | May 14, 2024 | Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Success... |
| CVE-2024-31480 | HIGH | 7.5 | 0.6% | May 14, 2024 | Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Success... |
| CVE-2024-31479 | HIGH | 7.5 | 0.6% | May 14, 2024 | Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAP... |
| CVE-2024-31478 | HIGH | 7.5 | 0.6% | May 14, 2024 | Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI prot... |
| CVE-2024-31477 | HIGH | 8.8 | 1.5% | May 14, 2024 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of... |
| CVE-2024-31476 | HIGH | 8.8 | 1.5% | May 14, 2024 | Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of... |
| CVE-2024-31475 | HIGH | 8.2 | 0.4% | May 14, 2024 | There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now