2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7574 | MEDIUM | 6.1 | 0.2% | Aug 12, 2024 | The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5... |
| CVE-2024-7512 | MEDIUM | 4.8 | 0.4% | Aug 12, 2024 | Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue adminis... |
| CVE-2024-7416 | MEDIUM | 5.3 | 0.5% | Aug 12, 2024 | The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7... |
| CVE-2024-7414 | MEDIUM | 5.3 | 0.6% | Aug 12, 2024 | The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includ... |
| CVE-2024-7413 | MEDIUM | 5.3 | 0.5% | Aug 12, 2024 | The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8... |
| CVE-2024-7412 | MEDIUM | 5.3 | 0.5% | Aug 12, 2024 | The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.1... |
| CVE-2024-7410 | MEDIUM | 5.3 | 0.5% | Aug 12, 2024 | The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includ... |
| CVE-2024-7408 | MEDIUM | 6.5 | 0.3% | Aug 12, 2024 | This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plai... |
| CVE-2024-7382 | MEDIUM | 5.3 | 0.5% | Aug 12, 2024 | The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1.... |
| CVE-2024-6759 | MEDIUM | 5.3 | 0.7% | Aug 12, 2024 | When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separa... |
| CVE-2024-6758 | MEDIUM | 6.5 | 0.4% | Aug 12, 2024 | Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low pri... |
| CVE-2024-6691 | MEDIUM | 4 | 0.3% | Aug 12, 2024 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr... |
| CVE-2024-6640 | MEDIUM | 6.3 | 0.5% | Aug 12, 2024 | In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Reques... |
| CVE-2024-6562 | MEDIUM | 5.3 | 0.6% | Aug 12, 2024 | The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all ver... |
| CVE-2024-6158 | MEDIUM | 4.8 | 0.4% | Aug 12, 2024 | The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4... |
| CVE-2024-6136 | MEDIUM | 5.4 | 0.2% | Aug 12, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could all... |
| CVE-2024-6134 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-6133 | MEDIUM | 6.5 | 0.4% | Aug 12, 2024 | The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin... |
| CVE-2024-5801 | MEDIUM | 5.3 | 0.3% | Aug 12, 2024 | Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise ... |
| CVE-2024-4360 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-4359 | MEDIUM | 6.5 | 0.5% | Aug 12, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-4350 | MEDIUM | 4.8 | 0.5% | Aug 12, 2024 | Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is s... |
| CVE-2024-43168 | MEDIUM | 4.8 | 0.3% | Aug 12, 2024 | DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, ... |
| CVE-2024-42367 | MEDIUM | 4.8 | 0.6% | Aug 12, 2024 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to ... |
| CVE-2024-42165 | MEDIUM | 5.4 | 0.4% | Aug 12, 2024 | Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accoun... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now