2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23488 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members... |
| CVE-2024-1887 | MEDIUM | 4.3 | 0.3% | Feb 29, 2024 | Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is... |
| CVE-2024-25594 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress De... |
| CVE-2024-25292 | CRITICAL | 9.6 | 1.5% | Feb 29, 2024 | Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2024-25291 | CRITICAL | 9.8 | 1.6% | Feb 29, 2024 | Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin. |
| CVE-2024-1982 | CRITICAL | 9.1 | 0.8% | Feb 29, 2024 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capa... |
| CVE-2024-1981 | CRITICAL | 9.1 | 1.1% | Feb 29, 2024 | The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' para... |
| CVE-2024-1978 | MEDIUM | 5.5 | 0.5% | Feb 29, 2024 | The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8.... |
| CVE-2024-25098 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB ... |
| CVE-2024-25094 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicola... |
| CVE-2024-25093 | MEDIUM | 6.1 | 0.4% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD ... |
| CVE-2024-24525 | CRITICAL | 9.8 | 1.1% | Feb 29, 2024 | An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code vi... |
| CVE-2024-23501 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Eboo... |
| CVE-2024-21752 | MEDIUM | 6.1 | 0.2% | Feb 29, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affe... |
| CVE-2024-1977 | MEDIUM | 4.8 | 0.4% | Feb 29, 2024 | The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist... |
| CVE-2024-1976 | MEDIUM | 4.3 | 0.2% | Feb 29, 2024 | The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2024-1437 | MEDIUM | 6.1 | 0.4% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Ads... |
| CVE-2024-1434 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Media A... |
| CVE-2024-1435 | HIGH | 7.5 | 0.5% | Feb 29, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainaca... |
| CVE-2024-1341 | MEDIUM | 5.4 | 0.3% | Feb 29, 2024 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe s... |
| CVE-2024-1468 | HIGH | 8.8 | 1.2% | Feb 29, 2024 | The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due ... |
| CVE-2024-0689 | MEDIUM | 4.8 | 0.3% | Feb 29, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versio... |
| CVE-2024-22871 | HIGH | 7.5 | 1.5% | Feb 29, 2024 | An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure... |
| CVE-2024-27517 | MEDIUM | 5.4 | 0.4% | Feb 29, 2024 | Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code afte... |
| CVE-2024-27516 | CRITICAL | 9.8 | 1.5% | Feb 29, 2024 | Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now