2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6270 | MEDIUM | 4.8 | 0.3% | Aug 5, 2024 | The Community Events WordPress plugin before 1.5.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-5081 | MEDIUM | 6.1 | 0.2% | Aug 5, 2024 | The wp-eMember WordPress plugin before v10.7.0 does not have CSRF check in some places, and is missing sanitisation as w... |
| CVE-2024-3636 | MEDIUM | 5.4 | 0.3% | Aug 5, 2024 | The Pinpoint Booking System WordPress plugin before 2.9.9.4.8 does not sanitise and escape some of its settings, which ... |
| CVE-2024-7466 | MEDIUM | 5.4 | 0.4% | Aug 5, 2024 | A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unkno... |
| CVE-2024-7453 | MEDIUM | 4.8 | 0.4% | Aug 4, 2024 | A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects u... |
| CVE-2024-6331 | MEDIUM | 6.5 | 0.5% | Aug 4, 2024 | stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI... |
| CVE-2024-7438 | MEDIUM | 4.3 | 0.5% | Aug 3, 2024 | A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability... |
| CVE-2024-37286 | MEDIUM | 6.5 | 0.4% | Aug 3, 2024 | APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_sh... |
| CVE-2024-7437 | MEDIUM | 4.3 | 0.4% | Aug 3, 2024 | A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown functio... |
| CVE-2024-38321 | MEDIUM | 6.5 | 0.4% | Aug 3, 2024 | IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log file... |
| CVE-2024-6872 | MEDIUM | 5.4 | 0.3% | Aug 3, 2024 | The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for ... |
| CVE-2024-6709 | MEDIUM | 4.3 | 0.3% | Aug 3, 2024 | The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-7356 | MEDIUM | 5.4 | 0.3% | Aug 3, 2024 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ paramete... |
| CVE-2024-6390 | MEDIUM | 5.9 | 0.3% | Aug 3, 2024 | The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz ... |
| CVE-2024-7319 | MEDIUM | 5 | 0.4% | Aug 2, 2024 | An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through... |
| CVE-2024-42349 | MEDIUM | 5.3 | 0.6% | Aug 2, 2024 | FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorize... |
| CVE-2024-38888 | MEDIUM | 6.8 | 0.2% | Aug 2, 2024 | An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows... |
| CVE-2024-33895 | MEDIUM | 6.6 | 0.5% | Aug 2, 2024 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the conf... |
| CVE-2024-33893 | MEDIUM | 6.1 | 0.7% | Aug 2, 2024 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displayin... |
| CVE-2024-41519 | MEDIUM | 5.4 | 0.4% | Aug 2, 2024 | Feripro <= v2.2.3 is vulnerable to Cross Site Scripting (XSS) via "/admin/programm/<program_id>/zuordnung/veranstaltunge... |
| CVE-2024-41517 | MEDIUM | 5.3 | 0.6% | Aug 2, 2024 | An Incorrect Access Control vulnerability in "/admin/benutzer/institution/rechteverwaltung/uebersicht" in Feripro <= v2.... |
| CVE-2024-7323 | MEDIUM | 6.5 | 0.6% | Aug 2, 2024 | Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately fi... |
| CVE-2024-7204 | MEDIUM | 6.1 | 0.3% | Aug 2, 2024 | Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into... |
| CVE-2024-6704 | MEDIUM | 6.1 | 0.5% | Aug 2, 2024 | The Comments – wpDiscuz plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 7.6.2... |
| CVE-2024-40723 | MEDIUM | 4.3 | 0.5% | Aug 2, 2024 | The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now