2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-44919 | MEDIUM | 5.4 | 0.3% | Aug 29, 2024 | A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute ar... |
| CVE-2024-43954 | MEDIUM | 6.3 | 0.3% | Aug 29, 2024 | Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.T... |
| CVE-2024-35118 | MEDIUM | 4.6 | 0.2% | Aug 29, 2024 | IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical a... |
| CVE-2024-8304 | MEDIUM | 4.9 | 0.6% | Aug 29, 2024 | A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an un... |
| CVE-2024-8303 | MEDIUM | 6.3 | 0.4% | Aug 29, 2024 | A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. T... |
| CVE-2024-43940 | MEDIUM | 6.5 | 0.4% | Aug 29, 2024 | Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr... |
| CVE-2024-43939 | MEDIUM | 6.5 | 0.3% | Aug 29, 2024 | Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr... |
| CVE-2024-1056 | MEDIUM | 5.4 | 0.2% | Aug 29, 2024 | The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe... |
| CVE-2024-1384 | MEDIUM | 5.4 | 0.4% | Aug 29, 2024 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-7895 | MEDIUM | 5.4 | 0.4% | Aug 29, 2024 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘t... |
| CVE-2024-7606 | MEDIUM | 5.4 | 0.3% | Aug 29, 2024 | The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' sho... |
| CVE-2024-7418 | MEDIUM | 4.3 | 0.5% | Aug 29, 2024 | The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to ... |
| CVE-2024-7132 | MEDIUM | 4.8 | 0.4% | Aug 29, 2024 | The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of i... |
| CVE-2024-6927 | MEDIUM | 4.8 | 0.4% | Aug 29, 2024 | The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high... |
| CVE-2024-6551 | MEDIUM | 5.3 | 0.3% | Aug 29, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all ... |
| CVE-2024-5987 | MEDIUM | 4.3 | 0.3% | Aug 29, 2024 | The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-5857 | MEDIUM | 5.3 | 0.3% | Aug 29, 2024 | The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress... |
| CVE-2024-5624 | MEDIUM | 6.1 | 0.2% | Aug 29, 2024 | Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based a... |
| CVE-2024-5417 | MEDIUM | 5.4 | 0.3% | Aug 29, 2024 | The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting the... |
| CVE-2024-45440 | MEDIUM | 5.3 | 9.3% | Aug 29, 2024 | core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash... |
| CVE-2024-43986 | MEDIUM | 4.8 | 0.3% | Aug 29, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople ... |
| CVE-2024-3944 | MEDIUM | 4.8 | 0.3% | Aug 29, 2024 | The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and in... |
| CVE-2024-38304 | MEDIUM | 6.5 | 0.1% | Aug 29, 2024 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of B... |
| CVE-2024-38303 | MEDIUM | 6 | 0.1% | Aug 29, 2024 | Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability.... |
| CVE-2024-7857 | MEDIUM | 6.5 | 0.5% | Aug 29, 2024 | The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now