2024 CVE Vulnerabilities
39,225 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6588 | MEDIUM | 6.4 | 0.4% | Jul 12, 2024 | The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2024-6555 | MEDIUM | 5.3 | 0.9% | Jul 12, 2024 | The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to... |
| CVE-2024-5811 | MEDIUM | 5.4 | 0.3% | Jul 12, 2024 | The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could ... |
| CVE-2024-5626 | MEDIUM | 6.1 | 0.4% | Jul 12, 2024 | The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2024-4753 | MEDIUM | 4.8 | 0.3% | Jul 12, 2024 | The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-3112 | MEDIUM | 4.8 | 0.4% | Jul 12, 2024 | The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowin... |
| CVE-2024-2696 | MEDIUM | 4.8 | 0.4% | Jul 12, 2024 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c... |
| CVE-2024-2640 | MEDIUM | 5.4 | 0.4% | Jul 12, 2024 | The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users... |
| CVE-2024-2430 | MEDIUM | 5.4 | 0.3% | Jul 12, 2024 | The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcod... |
| CVE-2024-0974 | MEDIUM | 4.8 | 0.3% | Jul 12, 2024 | The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-1375 | MEDIUM | 4.3 | 0.2% | Jul 12, 2024 | The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on t... |
| CVE-2024-6392 | MEDIUM | 5.4 | 0.3% | Jul 11, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modificat... |
| CVE-2024-6485 | MEDIUM | 6.4 | 0.5% | Jul 11, 2024 | A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vuln... |
| CVE-2024-39553 | MEDIUM | 6.9 | 0.4% | Jul 11, 2024 | An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allow... |
| CVE-2024-39539 | MEDIUM | 6 | 0.2% | Jul 11, 2024 | A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an u... |
| CVE-2024-39537 | MEDIUM | 6.9 | 0.3% | Jul 11, 2024 | An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve... |
| CVE-2024-39536 | MEDIUM | 6 | 0.2% | Jul 11, 2024 | A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Ju... |
| CVE-2024-39533 | MEDIUM | 6.9 | 0.3% | Jul 11, 2024 | An Unimplemented or Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX460... |
| CVE-2024-39532 | MEDIUM | 6.3 | 0.2% | Jul 11, 2024 | An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allo... |
| CVE-2024-39905 | MEDIUM | 5.3 | 0.4% | Jul 11, 2024 | Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_chann... |
| CVE-2024-39528 | MEDIUM | 6 | 0.3% | Jul 11, 2024 | A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved al... |
| CVE-2024-39317 | MEDIUM | 4.9 | 0.6% | Jul 11, 2024 | Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would resul... |
| CVE-2024-6035 | MEDIUM | 6.1 | 0.4% | Jul 11, 2024 | A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerabil... |
| CVE-2024-6528 | MEDIUM | 6.1 | 0.3% | Jul 11, 2024 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c... |
| CVE-2024-5680 | MEDIUM | 5.5 | 0.1% | Jul 11, 2024 | CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now