2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38670 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Member... |
| CVE-2024-37960 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chris Coyie... |
| CVE-2024-6491 | MEDIUM | 4.3 | 0.4% | Jul 20, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-6489 | MEDIUM | 5.3 | 0.3% | Jul 20, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-40347 | MEDIUM | 6.1 | 0.4% | Jul 20, 2024 | A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute ... |
| CVE-2024-3934 | MEDIUM | 6.5 | 0.7% | Jul 20, 2024 | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.... |
| CVE-2024-6560 | MEDIUM | 5.3 | 0.6% | Jul 20, 2024 | The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up ... |
| CVE-2024-2337 | MEDIUM | 5.4 | 0.3% | Jul 20, 2024 | The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_g... |
| CVE-2024-5804 | MEDIUM | 4.3 | 0.2% | Jul 20, 2024 | The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u... |
| CVE-2024-41599 | MEDIUM | 6.1 | 0.5% | Jul 19, 2024 | Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-41597 | MEDIUM | 4.2 | 0.3% | Jul 19, 2024 | Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: th... |
| CVE-2024-41124 | MEDIUM | 6.3 | 0.3% | Jul 19, 2024 | Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTP... |
| CVE-2024-39123 | MEDIUM | 5.4 | 21.5% | Jul 19, 2024 | In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due... |
| CVE-2024-29080 | MEDIUM | 6.5 | 0.1% | Jul 19, 2024 | Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En... |
| CVE-2024-24970 | MEDIUM | 6.5 | 0.1% | Jul 19, 2024 | Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En... |
| CVE-2024-6908 | MEDIUM | 6 | 0.3% | Jul 19, 2024 | Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin... |
| CVE-2024-6895 | MEDIUM | 6.1 | 0.2% | Jul 19, 2024 | Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compro... |
| CVE-2024-0006 | MEDIUM | 5.4 | 0.3% | Jul 19, 2024 | Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs t... |
| CVE-2024-6916 | MEDIUM | 5.5 | 0.1% | Jul 19, 2024 | A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a ... |
| CVE-2024-5977 | MEDIUM | 5.4 | 0.4% | Jul 19, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Refer... |
| CVE-2024-6907 | MEDIUM | 5.4 | 0.4% | Jul 19, 2024 | A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affecte... |
| CVE-2024-39457 | MEDIUM | 5.4 | 0.2% | Jul 19, 2024 | Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is expl... |
| CVE-2024-6799 | MEDIUM | 4.3 | 0.3% | Jul 19, 2024 | The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to... |
| CVE-2024-5604 | MEDIUM | 5.9 | 0.3% | Jul 19, 2024 | The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-21583 | MEDIUM | 4.1 | 0.6% | Jul 19, 2024 | Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now