2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38156 | MEDIUM | 6.1 | 0.4% | Jul 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-5997 | MEDIUM | 4.3 | 0.4% | Jul 18, 2024 | The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modificat... |
| CVE-2024-6455 | MEDIUM | 5.3 | 0.4% | Jul 18, 2024 | The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-39090 | MEDIUM | 6.1 | 0.5% | Jul 18, 2024 | The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forger... |
| CVE-2024-30126 | MEDIUM | 4.7 | 0.2% | Jul 18, 2024 | HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malic... |
| CVE-2024-5321 | MEDIUM | 6.1 | 0.3% | Jul 18, 2024 | A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read contai... |
| CVE-2024-5625 | MEDIUM | 6.5 | 0.4% | Jul 18, 2024 | Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console... |
| CVE-2024-30125 | MEDIUM | 6.2 | 0.1% | Jul 18, 2024 | HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the s... |
| CVE-2024-5620 | MEDIUM | 6.5 | 0.3% | Jul 18, 2024 | Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Cons... |
| CVE-2024-40648 | MEDIUM | 5.4 | 0.3% | Jul 18, 2024 | matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method... |
| CVE-2024-40647 | MEDIUM | 5.3 | 0.2% | Jul 18, 2024 | sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variabl... |
| CVE-2024-40644 | MEDIUM | 6.8 | 0.2% | Jul 18, 2024 | gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another... |
| CVE-2024-38302 | MEDIUM | 5.7 | 0.1% | Jul 18, 2024 | Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (St... |
| CVE-2024-30473 | MEDIUM | 6.5 | 0.3% | Jul 18, 2024 | Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privile... |
| CVE-2024-6504 | MEDIUM | 5.3 | 0.3% | Jul 18, 2024 | Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with netw... |
| CVE-2024-40725 | MEDIUM | 5.3 | 4.1% | Jul 18, 2024 | A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type b... |
| CVE-2024-5555 | MEDIUM | 6.4 | 0.5% | Jul 18, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-5554 | MEDIUM | 6.4 | 0.3% | Jul 18, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-6705 | MEDIUM | 5.5 | 0.3% | Jul 18, 2024 | The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,... |
| CVE-2024-6599 | MEDIUM | 4.3 | 0.3% | Jul 18, 2024 | The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capabil... |
| CVE-2024-6175 | MEDIUM | 5.4 | 0.3% | Jul 18, 2024 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modificati... |
| CVE-2024-5964 | MEDIUM | 6.4 | 0.3% | Jul 18, 2024 | The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme... |
| CVE-2024-39682 | MEDIUM | 5.4 | 0.4% | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up ... |
| CVE-2024-40402 | MEDIUM | 6.3 | 0.4% | Jul 17, 2024 | A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulne... |
| CVE-2024-39126 | MEDIUM | 5.4 | 0.3% | Jul 17, 2024 | Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now