2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-33975 | MEDIUM | 6.1 | 0.2% | Aug 6, 2024 | Cross-Site Scripting (XSS) vulnerability in E-Negosyo System affecting version 1.0. An attacker could exploit this vulne... |
| CVE-2024-7084 | MEDIUM | 4.8 | 0.4% | Aug 6, 2024 | The Ajax Search Lite WordPress plugin before 4.12.1 does not sanitise and escape some parameters, which could allow user... |
| CVE-2024-7082 | MEDIUM | 6.1 | 0.4% | Aug 6, 2024 | The Easy Table of Contents WordPress plugin before 2.0.68 does not sanitise and escape some parameters, which could allo... |
| CVE-2024-6766 | MEDIUM | 5.4 | 0.3% | Aug 6, 2024 | The shortcodes-ultimate-pro WordPress plugin before 7.2.1 does not validate and escape some of its shortcode attributes ... |
| CVE-2024-6651 | MEDIUM | 6.1 | 15.8% | Aug 6, 2024 | The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it b... |
| CVE-2024-6201 | MEDIUM | 5.3 | 0.3% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a Template Injection vulnerability within the engine used to generate em... |
| CVE-2024-6200 | MEDIUM | 5.4 | 0.3% | Aug 6, 2024 | HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScri... |
| CVE-2024-5708 | MEDIUM | 5.4 | 0.2% | Aug 6, 2024 | The WPBakery Visual Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter ... |
| CVE-2024-39817 | MEDIUM | 6.5 | 0.4% | Aug 6, 2024 | Insertion of sensitive information into sent data issue exists in Cybozu Office 10.0.0 to 10.8.6, which may allow a user... |
| CVE-2024-7008 | MEDIUM | 6.1 | 24.1% | Aug 6, 2024 | Unsanitized user-input in Calibre <= 7.15.0 allow attackers to perform reflected cross-site scripting. |
| CVE-2024-5963 | MEDIUM | 6.7 | 0.2% | Aug 6, 2024 | Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue... |
| CVE-2024-7537 | MEDIUM | 5.5 | 0.3% | Aug 6, 2024 | oFono QMI SMS Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows local attacker... |
| CVE-2024-34343 | MEDIUM | 6.1 | 0.4% | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. The `navigateTo... |
| CVE-2024-41960 | MEDIUM | 4.8 | 0.3% | Aug 5, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a Ja... |
| CVE-2024-41959 | MEDIUM | 6.1 | 0.3% | Aug 5, 2024 | mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a Ja... |
| CVE-2024-41820 | MEDIUM | 6 | 0.4% | Aug 5, 2024 | Kubean is a cluster lifecycle management toolchain based on kubespray and other cluster LCM engine. The ClusterRole has ... |
| CVE-2024-41816 | MEDIUM | 5.4 | 0.4% | Aug 5, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Persistent Cross-Site Scriptin... |
| CVE-2024-6361 | MEDIUM | 5.4 | 0.2% | Aug 5, 2024 | Improper Neutralization vulnerability (XSS) has been discovered in OpenText™ ALM Octane. The vulnerability affects all v... |
| CVE-2024-41381 | MEDIUM | 6.1 | 0.3% | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\settings\ad... |
| CVE-2024-41380 | MEDIUM | 6.1 | 0.3% | Aug 5, 2024 | microweber 2.0.16 was discovered to contain a Cross Site Scripting (XSS) vulnerability via userfiles\modules\tags\add_ta... |
| CVE-2024-41200 | MEDIUM | 5.5 | 0.2% | Aug 5, 2024 | A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. |
| CVE-2024-23357 | MEDIUM | 5.5 | 0.1% | Aug 5, 2024 | Transient DOS while importing a PKCS#8-encoded RSA key with zero bytes modulus. |
| CVE-2024-23350 | MEDIUM | 6.5 | 0.2% | Aug 5, 2024 | Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integr... |
| CVE-2024-6710 | MEDIUM | 5.4 | 0.3% | Aug 5, 2024 | The Ditty WordPress plugin before 3.1.45 does not sanitise and escape some parameters, which could allow users with a r... |
| CVE-2024-6498 | MEDIUM | 4.8 | 0.3% | Aug 5, 2024 | The Chatbot for WordPress by Collect.chat ⚡️ WordPress plugin before 2.4.4 does not sanitise and escape some of its sett... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now