2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33944 | MEDIUM | 6.5 | 0.5% | May 2, 2024 | Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce... |
| CVE-2024-3005 | MEDIUM | 6.4 | 0.3% | May 2, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-33930 | MEDIUM | 4.7 | 0.4% | May 2, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share Thi... |
| CVE-2024-33922 | MEDIUM | 5.3 | 0.4% | May 2, 2024 | Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Medi... |
| CVE-2024-33913 | CRITICAL | 9.6 | 0.3% | May 2, 2024 | Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects ... |
| CVE-2024-33911 | HIGH | 7.2 | 1.1% | May 2, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Ma... |
| CVE-2024-3955 | CRITICAL | 9.8 | 1.1% | May 2, 2024 | URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subs... |
| CVE-2024-32638 | MEDIUM | 6.3 | 1.1% | May 2, 2024 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forwa... |
| CVE-2024-3883 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all vers... |
| CVE-2024-32114 | HIGH | 8.8 | 6.9% | May 2, 2024 | In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and... |
| CVE-2024-3280 | MEDIUM | 6.4 | 0.3% | May 2, 2024 | The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us... |
| CVE-2024-3490 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-round... |
| CVE-2024-32971 | CRITICAL | 9 | 0.7% | May 2, 2024 | Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation ... |
| CVE-2024-32962 | CRITICAL | 10 | 0.8% | May 2, 2024 | xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuratio... |
| CVE-2024-32882 | LOW | 2.7 | 0.5% | May 2, 2024 | Wagtail is an open source content management system built on Django. In affected versions if a model has been made avail... |
| CVE-2024-3481 | MEDIUM | 5.2 | 0.3% | May 2, 2024 | The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attacke... |
| CVE-2024-3478 | MEDIUM | 6.1 | 0.2% | May 2, 2024 | The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attack... |
| CVE-2024-3477 | MEDIUM | 4.3 | 0.3% | May 2, 2024 | The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers... |
| CVE-2024-3476 | HIGH | 8.8 | 0.4% | May 2, 2024 | The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow atta... |
| CVE-2024-3475 | HIGH | 7.5 | 0.3% | May 2, 2024 | The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow atta... |
| CVE-2024-3474 | HIGH | 8.8 | 0.4% | May 2, 2024 | The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow at... |
| CVE-2024-3472 | MEDIUM | 5.9 | 0.2% | May 2, 2024 | The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which coul... |
| CVE-2024-3471 | LOW | 3.4 | 0.2% | May 2, 2024 | The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allo... |
| CVE-2024-2405 | MEDIUM | 4.5 | 0.3% | May 2, 2024 | The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers ... |
| CVE-2024-4142 | CRITICAL | 9 | 0.7% | May 1, 2024 | An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog A... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now