2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35119 | MEDIUM | 5.3 | 0.4% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2024-28798 | MEDIUM | 6.1 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2024-5062 | MEDIUM | 6.1 | 0.4% | Jun 30, 2024 | A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability ... |
| CVE-2024-28795 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2024-6415 | MEDIUM | 5.1 | 0.3% | Jun 30, 2024 | A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is a... |
| CVE-2024-6414 | MEDIUM | 6.9 | 0.6% | Jun 30, 2024 | A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown fun... |
| CVE-2024-5819 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Store... |
| CVE-2024-6363 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortco... |
| CVE-2024-5790 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute... |
| CVE-2024-5666 | MEDIUM | 5.4 | 0.4% | Jun 29, 2024 | The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter w... |
| CVE-2024-5942 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an... |
| CVE-2024-5889 | MEDIUM | 6.1 | 0.3% | Jun 29, 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2024-5192 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ... |
| CVE-2024-6405 | MEDIUM | 5.4 | 0.2% | Jun 29, 2024 | The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2024-39828 | MEDIUM | 6.1 | 0.4% | Jun 28, 2024 | R74n Sandboxels 1.9 through 1.9.5 allows XSS via a message in a modified saved-game file. This was fixed in a hotfix to ... |
| CVE-2024-38533 | MEDIUM | 6.5 | 0.3% | Jun 28, 2024 | ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. There is possible invalid stack access... |
| CVE-2024-38518 | MEDIUM | 4.6 | 0.3% | Jun 28, 2024 | BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker with a... |
| CVE-2024-29040 | MEDIUM | 4.3 | 0.3% | Jun 28, 2024 | This repository hosts source code implementing the Trusted Computing Group's (TCG) TPM2 Software Stack (TSS). The JSON Q... |
| CVE-2024-35156 | MEDIUM | 6.5 | 0.5% | Jun 28, 2024 | IBM MQ 9.3 LTS and 9.3 CD could allow a remote attacker to obtain sensitive information when a detailed technical error ... |
| CVE-2024-25053 | MEDIUM | 5.9 | 0.3% | Jun 28, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certif... |
| CVE-2024-25041 | MEDIUM | 5.4 | 0.4% | Jun 28, 2024 | IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is potentially vulnerable to cro... |
| CVE-2024-25031 | MEDIUM | 6.5 | 0.2% | Jun 28, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.4 uses an inadequate account lockout setting that could allo... |
| CVE-2024-35155 | MEDIUM | 6.5 | 0.6% | Jun 28, 2024 | IBM MQ Console 9.3 LTS and 9.3 CD could disclose could allow a remote attacker to obtain sensitive information when a de... |
| CVE-2024-38522 | MEDIUM | 6.3 | 0.3% | Jun 28, 2024 | Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The CSP policy ap... |
| CVE-2024-38521 | MEDIUM | 6.1 | 0.4% | Jun 28, 2024 | Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now