2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-41697 | MEDIUM | 6.1 | 0.3% | Aug 20, 2024 | Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) |
| CVE-2024-25009 | MEDIUM | 6.5 | 0.3% | Aug 20, 2024 | Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where im... |
| CVE-2024-7054 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress... |
| CVE-2024-38808 | MEDIUM | 4.3 | 0.5% | Aug 20, 2024 | In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a speci... |
| CVE-2024-5576 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carouse... |
| CVE-2024-6864 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute... |
| CVE-2024-7782 | MEDIUM | 6.5 | 0.9% | Aug 20, 2024 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-7775 | MEDIUM | 4.8 | 0.2% | Aug 20, 2024 | The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil... |
| CVE-2024-6575 | MEDIUM | 5.4 | 0.3% | Aug 20, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-5763 | MEDIUM | 5.4 | 0.4% | Aug 20, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-7948 | MEDIUM | 5.4 | 0.4% | Aug 20, 2024 | A vulnerability classified as problematic was found in SourceCodester Accounts Manager App 1.0. This vulnerability affec... |
| CVE-2024-7945 | MEDIUM | 5.4 | 0.5% | Aug 20, 2024 | A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been declared as problematic. A... |
| CVE-2024-7850 | MEDIUM | 6.1 | 0.2% | Aug 20, 2024 | The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2024-5941 | MEDIUM | 5.4 | 0.4% | Aug 20, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and dele... |
| CVE-2024-5940 | MEDIUM | 5.3 | 0.5% | Aug 20, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2024-5939 | MEDIUM | 5.3 | 0.5% | Aug 20, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data ... |
| CVE-2024-7942 | MEDIUM | 5.4 | 0.4% | Aug 20, 2024 | A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerabilit... |
| CVE-2024-7929 | MEDIUM | 6.1 | 0.5% | Aug 19, 2024 | A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects... |
| CVE-2024-4785 | MEDIUM | 6.5 | 0.5% | Aug 19, 2024 | BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero |
| CVE-2024-35539 | MEDIUM | 6.5 | 1.4% | Aug 19, 2024 | Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil... |
| CVE-2024-35538 | MEDIUM | 5.3 | 0.6% | Aug 19, 2024 | Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP ... |
| CVE-2024-43326 | MEDIUM | 5.4 | 0.3% | Aug 19, 2024 | Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constr... |
| CVE-2024-43317 | MEDIUM | 6.1 | 0.3% | Aug 19, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss U... |
| CVE-2024-23729 | MEDIUM | 6.1 | 0.4% | Aug 19, 2024 | The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute ... |
| CVE-2024-43281 | MEDIUM | 5.3 | 0.5% | Aug 19, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Element... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now