2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0740 | CRITICAL | 9.8 | 1.2% | Apr 26, 2024 | Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vuln... |
| CVE-2024-4198 | LOW | 2.7 | 0.5% | Apr 26, 2024 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows ... |
| CVE-2024-4195 | LOW | 2.7 | 0.5% | Apr 26, 2024 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows... |
| CVE-2024-4183 | MEDIUM | 6.5 | 0.6% | Apr 26, 2024 | Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the nu... |
| CVE-2024-4182 | MEDIUM | 4.3 | 0.6% | Apr 26, 2024 | Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing e... |
| CVE-2024-3962 | CRITICAL | 9.8 | 1.4% | Apr 26, 2024 | The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ... |
| CVE-2024-32046 | MEDIUM | 4.3 | 0.5% | Apr 26, 2024 | Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error mes... |
| CVE-2024-22091 | MEDIUM | 6.5 | 0.5% | Apr 26, 2024 | Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a requ... |
| CVE-2024-1789 | HIGH | 7.2 | 0.5% | Apr 26, 2024 | The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due ... |
| CVE-2024-3890 | MEDIUM | 5.4 | 0.3% | Apr 26, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget... |
| CVE-2024-3678 | MEDIUM | 5.3 | 0.6% | Apr 26, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure... |
| CVE-2024-33651 | HIGH | 8.8 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : fr... |
| CVE-2024-33650 | MEDIUM | 4.3 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: fr... |
| CVE-2024-33642 | MEDIUM | 5.9 | 0.4% | Apr 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Pos... |
| CVE-2024-33639 | MEDIUM | 4.8 | 0.4% | Apr 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAl... |
| CVE-2024-33638 | MEDIUM | 5.4 | 0.2% | Apr 26, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maint... |
| CVE-2024-33598 | MEDIUM | 5.9 | 0.4% | Apr 26, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annua... |
| CVE-2024-2920 | MEDIUM | 5.3 | 0.5% | Apr 26, 2024 | The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-4056 | HIGH | 7.5 | 0.8% | Apr 26, 2024 | Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allow... |
| CVE-2024-3188 | MEDIUM | 6.3 | 0.4% | Apr 26, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its sh... |
| CVE-2024-3075 | HIGH | 8.1 | 0.6% | Apr 26, 2024 | The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before o... |
| CVE-2024-3060 | MEDIUM | 4.5 | 0.5% | Apr 26, 2024 | The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL stat... |
| CVE-2024-3059 | MEDIUM | 5.7 | 0.3% | Apr 26, 2024 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers ... |
| CVE-2024-3058 | MEDIUM | 5.4 | 0.2% | Apr 26, 2024 | The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation a... |
| CVE-2024-3048 | MEDIUM | 5.5 | 0.4% | Apr 26, 2024 | The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leadin... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now