2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31971 | MEDIUM | 4.8 | 0.4% | Jul 24, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote at... |
| CVE-2024-5818 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via... |
| CVE-2024-3896 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2024-6896 | MEDIUM | 5.4 | 0.3% | Jul 24, 2024 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File... |
| CVE-2024-7065 | MEDIUM | 4.3 | 0.3% | Jul 24, 2024 | A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown funct... |
| CVE-2024-6930 | MEDIUM | 5.4 | 0.3% | Jul 24, 2024 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute withi... |
| CVE-2024-6874 | MEDIUM | 4.3 | 0.8% | Jul 24, 2024 | libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to... |
| CVE-2024-3297 | MEDIUM | 6.5 | 0.2% | Jul 24, 2024 | An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between... |
| CVE-2024-6629 | MEDIUM | 5.4 | 0.3% | Jul 24, 2024 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video sh... |
| CVE-2024-6571 | MEDIUM | 5.3 | 0.4% | Jul 24, 2024 | The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosu... |
| CVE-2024-6553 | MEDIUM | 5.3 | 0.4% | Jul 24, 2024 | The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all version... |
| CVE-2024-6836 | MEDIUM | 4.3 | 0.3% | Jul 24, 2024 | The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ... |
| CVE-2024-6094 | MEDIUM | 4.8 | 0.4% | Jul 24, 2024 | The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-40767 | MEDIUM | 6.5 | 0.9% | Jul 24, 2024 | In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actuall... |
| CVE-2024-5861 | MEDIUM | 6.5 | 0.4% | Jul 24, 2024 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a mi... |
| CVE-2024-3246 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2024-6755 | MEDIUM | 5.3 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing... |
| CVE-2024-6754 | MEDIUM | 4.3 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c... |
| CVE-2024-6753 | MEDIUM | 6.1 | 0.8% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in... |
| CVE-2024-6752 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in ... |
| CVE-2024-6751 | MEDIUM | 6.5 | 0.2% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2024-41656 | MEDIUM | 5.4 | 0.4% | Jul 23, 2024 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1,... |
| CVE-2024-41665 | MEDIUM | 5.4 | 0.4% | Jul 23, 2024 | Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnera... |
| CVE-2024-41664 | MEDIUM | 5.4 | 0.4% | Jul 23, 2024 | Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a ... |
| CVE-2024-39702 | MEDIUM | 5.9 | 0.6% | Jul 23, 2024 | In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now