2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33562 | HIGH | 7.1 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore allo... |
| CVE-2024-33559 | CRITICAL | 9.3 | 3.6% | Apr 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allo... |
| CVE-2024-33554 | MEDIUM | 6.1 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8theme XStore Core... |
| CVE-2024-33551 | CRITICAL | 9.8 | 0.6% | Apr 29, 2024 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core... |
| CVE-2024-33548 | HIGH | 7.1 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA-Team WZone allo... |
| CVE-2024-33542 | MEDIUM | 4.3 | 0.4% | Apr 29, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider.This issue affects Crelly ... |
| CVE-2024-33540 | MEDIUM | 6.5 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill ColorNe... |
| CVE-2024-33539 | MEDIUM | 5.4 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addo... |
| CVE-2024-33537 | MEDIUM | 6.5 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Horse WP Por... |
| CVE-2024-2505 | HIGH | 8.1 | 0.6% | Apr 29, 2024 | The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its setting... |
| CVE-2024-1905 | MEDIUM | 5.9 | 0.5% | Apr 29, 2024 | The Smart Forms WordPress plugin before 2.6.96 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-33649 | MEDIUM | 6.5 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widget... |
| CVE-2024-33648 | MEDIUM | 6.5 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kemory Grubb Recen... |
| CVE-2024-33646 | HIGH | 7.1 | 0.2% | Apr 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Sticky Anything allows Cross-Site Scripting (XSS).This ... |
| CVE-2024-33645 | HIGH | 7.1 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eftakhairul Islam ... |
| CVE-2024-33643 | MEDIUM | 5.9 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kailey Lampert Adv... |
| CVE-2024-33640 | MEDIUM | 6.5 | 0.3% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LBell Pretty Googl... |
| CVE-2024-33633 | HIGH | 7.1 | 0.4% | Apr 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Ad... |
| CVE-2024-33339 | — | — | — | Apr 29, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-4301 | HIGH | 8.8 | 1.1% | Apr 29, 2024 | N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with nor... |
| CVE-2024-4300 | CRITICAL | 9.8 | 0.8% | Apr 29, 2024 | E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the data... |
| CVE-2024-4299 | HIGH | 7.2 | 2.1% | Apr 29, 2024 | The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filt... |
| CVE-2024-3096 | MEDIUM | 6.5 | 1.5% | Apr 29, 2024 | In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() ... |
| CVE-2024-2757 | HIGH | 7.5 | 1.9% | Apr 29, 2024 | In PHP 8.3.* before 8.3.5, function mb_encode_mimeheader() runs endlessly for some inputs that contain long strings of n... |
| CVE-2024-2756 | MEDIUM | 6.5 | 37.9% | Apr 29, 2024 | Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site at... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now