2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8337 | MEDIUM | 5.4 | 0.4% | Aug 30, 2024 | A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VC... |
| CVE-2024-8274 | MEDIUM | 6.1 | 0.5% | Aug 30, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from... |
| CVE-2024-7858 | MEDIUM | 6.3 | 0.3% | Aug 30, 2024 | The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on ... |
| CVE-2024-7122 | MEDIUM | 5.4 | 0.4% | Aug 30, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a... |
| CVE-2024-8319 | MEDIUM | 4.3 | 0.2% | Aug 30, 2024 | The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11.... |
| CVE-2024-44944 | MEDIUM | 5.5 | 0.2% | Aug 30, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calcul... |
| CVE-2024-42412 | MEDIUM | 6.1 | 0.2% | Aug 30, 2024 | Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in... |
| CVE-2024-34577 | MEDIUM | 6.1 | 0.2% | Aug 30, 2024 | Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to ... |
| CVE-2024-5879 | MEDIUM | 5.4 | 0.4% | Aug 30, 2024 | The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-3998 | MEDIUM | 5.4 | 0.2% | Aug 30, 2024 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a... |
| CVE-2024-5061 | MEDIUM | 5.4 | 0.3% | Aug 30, 2024 | The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wr... |
| CVE-2024-5024 | MEDIUM | 6.1 | 0.3% | Aug 30, 2024 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr... |
| CVE-2024-4401 | MEDIUM | 5.4 | 0.3% | Aug 30, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_sli... |
| CVE-2024-8328 | MEDIUM | 5.4 | 0.3% | Aug 30, 2024 | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific pa... |
| CVE-2024-1543 | MEDIUM | 5.5 | 0.2% | Aug 29, 2024 | The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacke... |
| CVE-2024-41349 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php. |
| CVE-2024-41371 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php. |
| CVE-2024-41358 | MEDIUM | 6.1 | 1.5% | Aug 29, 2024 | phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php. |
| CVE-2024-41351 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php |
| CVE-2024-41350 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php |
| CVE-2024-41348 | MEDIUM | 6.1 | 0.4% | Aug 29, 2024 | openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php |
| CVE-2024-41347 | MEDIUM | 6.1 | 0.3% | Aug 29, 2024 | openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php |
| CVE-2024-41346 | MEDIUM | 5.4 | 0.3% | Aug 29, 2024 | openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php |
| CVE-2024-41345 | MEDIUM | 5.4 | 0.3% | Aug 29, 2024 | openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php |
| CVE-2024-34018 | MEDIUM | 5.5 | 0.1% | Aug 29, 2024 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap D... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now