2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29977 | MEDIUM | 4.3 | 0.3% | Aug 1, 2024 | Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are ... |
| CVE-2024-6923 | MEDIUM | 5.5 | 0.7% | Aug 1, 2024 | There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email ... |
| CVE-2024-2455 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2024-6346 | MEDIUM | 5.4 | 0.3% | Aug 1, 2024 | The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-38490 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta... |
| CVE-2024-38489 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attack... |
| CVE-2024-38481 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attac... |
| CVE-2024-25948 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta... |
| CVE-2024-7302 | MEDIUM | 5.4 | 0.4% | Aug 1, 2024 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
| CVE-2024-5678 | MEDIUM | 4.7 | 2.5% | Aug 1, 2024 | Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL ... |
| CVE-2024-5331 | MEDIUM | 4.3 | 0.2% | Aug 1, 2024 | The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1... |
| CVE-2024-5330 | MEDIUM | 5.4 | 0.2% | Aug 1, 2024 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache... |
| CVE-2024-25947 | MEDIUM | 4.4 | 0.2% | Aug 1, 2024 | Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local atta... |
| CVE-2024-6496 | MEDIUM | 6.5 | 0.3% | Aug 1, 2024 | The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers... |
| CVE-2024-4090 | MEDIUM | 4.8 | 0.4% | Aug 1, 2024 | The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin ... |
| CVE-2024-2872 | MEDIUM | 4.8 | 0.3% | Aug 1, 2024 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c... |
| CVE-2024-2843 | MEDIUM | 6.5 | 0.2% | Aug 1, 2024 | The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could all... |
| CVE-2024-1747 | MEDIUM | 6.5 | 0.2% | Aug 1, 2024 | The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX acti... |
| CVE-2024-7343 | MEDIUM | 6.1 | 0.4% | Aug 1, 2024 | A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknow... |
| CVE-2024-7342 | MEDIUM | 6.1 | 0.4% | Aug 1, 2024 | A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part ... |
| CVE-2024-2090 | MEDIUM | 6.4 | 0.3% | Aug 1, 2024 | The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an... |
| CVE-2024-7339 | MEDIUM | 5.3 | 32.0% | Aug 1, 2024 | A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION... |
| CVE-2024-39607 | MEDIUM | 6.8 | 0.8% | Aug 1, 2024 | OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the... |
| CVE-2024-34021 | MEDIUM | 6.8 | 0.4% | Aug 1, 2024 | Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted... |
| CVE-2024-7330 | MEDIUM | 6.3 | 0.5% | Aug 1, 2024 | A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the functio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now