2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6340 | MEDIUM | 5.4 | 0.4% | Jul 3, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun... |
| CVE-2024-6263 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver... |
| CVE-2024-4482 | MEDIUM | 5.4 | 0.4% | Jul 3, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-2375 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could all... |
| CVE-2024-2235 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use... |
| CVE-2024-2234 | MEDIUM | 5.4 | 0.3% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high pr... |
| CVE-2024-2233 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make log... |
| CVE-2024-2231 | MEDIUM | 6.5 | 0.4% | Jul 3, 2024 | The allows any authenticated user to join a private group due to a missing authorization check on a function |
| CVE-2024-2040 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use... |
| CVE-2024-4543 | MEDIUM | 4.3 | 0.2% | Jul 3, 2024 | The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2024-39920 | MEDIUM | 4.3 | 0.6% | Jul 3, 2024 | The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of... |
| CVE-2024-32673 | MEDIUM | 6.7 | 0.2% | Jul 3, 2024 | Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segme... |
| CVE-2024-39326 | MEDIUM | 4.4 | 0.3% | Jul 2, 2024 | SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectnam... |
| CVE-2024-39325 | MEDIUM | 5.3 | 0.4% | Jul 2, 2024 | aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 202... |
| CVE-2024-39322 | MEDIUM | 5.5 | 0.5% | Jul 2, 2024 | aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 202... |
| CVE-2024-39315 | MEDIUM | 6.5 | 0.4% | Jul 2, 2024 | Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pome... |
| CVE-2024-6381 | MEDIUM | 5.3 | 0.4% | Jul 2, 2024 | The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function ... |
| CVE-2024-39891 | MEDIUM | 5.3 | 1.5% | Jul 2, 2024 | In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoin... |
| CVE-2024-5866 | MEDIUM | 4.3 | 0.4% | Jul 2, 2024 | Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner... |
| CVE-2024-5865 | MEDIUM | 6.5 | 0.5% | Jul 2, 2024 | Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner... |
| CVE-2024-39316 | MEDIUM | 6.5 | 0.9% | Jul 2, 2024 | Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression De... |
| CVE-2024-25087 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue sc... |
| CVE-2024-22105 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue sc... |
| CVE-2024-32932 | MEDIUM | 6.8 | 0.4% | Jul 2, 2024 | Under certain circumstances the web interface users credentials may be recovered by an authenticated user. |
| CVE-2024-22104 | MEDIUM | 5.5 | 0.2% | Jul 2, 2024 | Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now