2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3556 | — | — | — | Apr 9, 2024 | Rejected reason: Duplicate of CVE-2024-3557 |
| CVE-2024-3446 | HIGH | 8.2 | 0.3% | Apr 9, 2024 | A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the m... |
| CVE-2024-27665 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module. |
| CVE-2024-3545 | MEDIUM | 4.3 | 0.3% | Apr 9, 2024 | Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earl... |
| CVE-2024-3514 | — | — | — | Apr 9, 2024 | Rejected reason: **DUPLICATE** Please use CVE-2024-1846 instead. |
| CVE-2024-3512 | — | — | — | Apr 9, 2024 | Rejected reason: **DUPLICATE*** Please use CVE-2024-2583 instead. |
| CVE-2024-3267 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_lis... |
| CVE-2024-3266 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets... |
| CVE-2024-3244 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute... |
| CVE-2024-3214 | CRITICAL | 9.8 | 0.8% | Apr 9, 2024 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and includin... |
| CVE-2024-3213 | HIGH | 8.2 | 0.8% | Apr 9, 2024 | The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2024-3208 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery... |
| CVE-2024-3167 | MEDIUM | 6.4 | 0.5% | Apr 9, 2024 | The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter i... |
| CVE-2024-3136 | CRITICAL | 9.8 | 5.0% | Apr 9, 2024 | The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3... |
| CVE-2024-3097 | MEDIUM | 5.3 | 38.0% | Apr 9, 2024 | The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to ... |
| CVE-2024-3093 | — | — | — | Apr 9, 2024 | Rejected reason: ** DUPLICATE ** Accidental request. Please use CVE-2024-1752 instead. |
| CVE-2024-3064 | MEDIUM | 6.4 | 0.4% | Apr 9, 2024 | The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-3053 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Sit... |
| CVE-2024-30706 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-2974 | MEDIUM | 5.3 | 0.5% | Apr 9, 2024 | The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress... |
| CVE-2024-2957 | — | — | — | Apr 9, 2024 | Rejected reason: **DUPLICATE*** Please use CVE-2024-1983 instead. |
| CVE-2024-2946 | MEDIUM | 5.4 | 0.3% | Apr 9, 2024 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2024-2918 | LOW | 3.6 | 0.2% | Apr 9, 2024 | Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker wit... |
| CVE-2024-2871 | HIGH | 7.7 | 0.5% | Apr 9, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver... |
| CVE-2024-2866 | — | — | — | Apr 9, 2024 | Rejected reason: ** REJECT ** Accidental reservation. Please use CVE-2024-2509. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now