2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5457 | MEDIUM | 5.4 | 0.4% | Jul 9, 2024 | The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions... |
| CVE-2024-4868 | MEDIUM | 5.4 | 0.4% | Jul 9, 2024 | The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Event... |
| CVE-2024-4102 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on... |
| CVE-2024-4100 | MEDIUM | 5.3 | 0.2% | Jul 9, 2024 | The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2024-3608 | MEDIUM | 5.3 | 0.6% | Jul 9, 2024 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o... |
| CVE-2024-3603 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' sho... |
| CVE-2024-3563 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in a... |
| CVE-2024-3228 | MEDIUM | 5.3 | 0.4% | Jul 9, 2024 | The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i... |
| CVE-2024-5881 | MEDIUM | 6.4 | 0.3% | Jul 9, 2024 | The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc... |
| CVE-2024-37923 | MEDIUM | 5.4 | 0.2% | Jul 9, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.T... |
| CVE-2024-6334 | MEDIUM | 6.1 | 0.4% | Jul 9, 2024 | The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-5802 | MEDIUM | 4.8 | 0.4% | Jul 9, 2024 | The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-3410 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-6171 | MEDIUM | 5.3 | 0.2% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address ... |
| CVE-2024-6170 | MEDIUM | 5.4 | 0.5% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-6169 | MEDIUM | 5.4 | 0.5% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-4667 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-39600 | MEDIUM | 4.2 | 0.1% | Jul 9, 2024 | Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which... |
| CVE-2024-39599 | MEDIUM | 4.7 | 0.3% | Jul 9, 2024 | Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can by... |
| CVE-2024-39596 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which ... |
| CVE-2024-39595 | MEDIUM | 5.4 | 0.2% | Jul 9, 2024 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled input... |
| CVE-2024-39594 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled input... |
| CVE-2024-37180 | MEDIUM | 5.3 | 0.3% | Jul 9, 2024 | Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote... |
| CVE-2024-37175 | MEDIUM | 6.5 | 0.3% | Jul 9, 2024 | SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of p... |
| CVE-2024-37172 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated us... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now