2024 CVE Vulnerabilities
39,243 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3680 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2024-3595 | MEDIUM | 6.4 | 0.4% | May 14, 2024 | The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purec... |
| CVE-2024-3590 | MEDIUM | 6.1 | 0.2% | May 14, 2024 | The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to... |
| CVE-2024-3582 | MEDIUM | 4.8 | 0.2% | May 14, 2024 | The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as wel... |
| CVE-2024-3547 | MEDIUM | 6.1 | 0.4% | May 14, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C... |
| CVE-2024-3462 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorizati... |
| CVE-2024-3461 | MEDIUM | 5.5 | 0.3% | May 14, 2024 | KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application fro... |
| CVE-2024-3460 | HIGH | 7 | 0.3% | May 14, 2024 | In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened app... |
| CVE-2024-3459 | HIGH | 7.8 | 0.3% | May 14, 2024 | KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by... |
| CVE-2024-3263 | CRITICAL | 9.8 | 0.8% | May 14, 2024 | YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combinatio... |
| CVE-2024-3239 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape som... |
| CVE-2024-3070 | CRITICAL | 9.8 | 1.2% | May 14, 2024 | The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an... |
| CVE-2024-3068 | MEDIUM | 4.8 | 0.6% | May 14, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' ... |
| CVE-2024-3055 | HIGH | 8.8 | 0.8% | May 14, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ... |
| CVE-2024-3037 | HIGH | 7.8 | 0.4% | May 14, 2024 | An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print... |
| CVE-2024-3016 | CRITICAL | 9.1 | 0.7% | May 14, 2024 | NEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5.4.0.0 – v5.6.0.20 allows an attacker to access a non-docume... |
| CVE-2024-35205 | HIGH | 7.8 | 0.8% | May 14, 2024 | The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names befo... |
| CVE-2024-35204 | HIGH | 8.4 | 0.2% | May 14, 2024 | Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus lo... |
| CVE-2024-35172 | MEDIUM | 4.4 | 0.4% | May 14, 2024 | Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.Thi... |
| CVE-2024-35171 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Acade... |
| CVE-2024-35170 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Stick... |
| CVE-2024-35169 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_bloc... |
| CVE-2024-35167 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's ... |
| CVE-2024-35166 | HIGH | 7.5 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Fileb... |
| CVE-2024-35165 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now