2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35139 | MEDIUM | 5.5 | 0.2% | Jun 28, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information fr... |
| CVE-2024-35137 | MEDIUM | 6.2 | 0.3% | Jun 28, 2024 | IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileg... |
| CVE-2024-3801 | MEDIUM | 6.1 | 0.3% | Jun 28, 2024 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET h... |
| CVE-2024-3800 | MEDIUM | 6.1 | 0.3% | Jun 28, 2024 | Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested fi... |
| CVE-2024-37741 | MEDIUM | 5.4 | 0.3% | Jun 28, 2024 | OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture. |
| CVE-2024-5737 | MEDIUM | 6.1 | 1.1% | Jun 28, 2024 | Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/ht... |
| CVE-2024-5925 | MEDIUM | 6.4 | 0.3% | Jun 28, 2024 | The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them... |
| CVE-2024-5922 | MEDIUM | 6.4 | 0.3% | Jun 28, 2024 | The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them... |
| CVE-2024-5662 | MEDIUM | 6.4 | 0.4% | Jun 28, 2024 | The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline,... |
| CVE-2024-5424 | MEDIUM | 6.4 | 0.5% | Jun 28, 2024 | The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga... |
| CVE-2024-6288 | MEDIUM | 4.7 | 0.4% | Jun 28, 2024 | The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress... |
| CVE-2024-5796 | MEDIUM | 6.4 | 0.3% | Jun 28, 2024 | The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all ver... |
| CVE-2024-5788 | MEDIUM | 6.4 | 0.3% | Jun 28, 2024 | The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's... |
| CVE-2024-39347 | MEDIUM | 5.9 | 0.5% | Jun 28, 2024 | Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227... |
| CVE-2024-2795 | MEDIUM | 5.3 | 0.5% | Jun 28, 2024 | The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2... |
| CVE-2024-5730 | MEDIUM | 6.1 | 0.4% | Jun 28, 2024 | The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2024-5729 | MEDIUM | 6.1 | 0.5% | Jun 28, 2024 | The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2024-5728 | MEDIUM | 5.4 | 0.5% | Jun 28, 2024 | The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back i... |
| CVE-2024-5727 | MEDIUM | 4.7 | 0.6% | Jun 28, 2024 | The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the... |
| CVE-2024-5570 | MEDIUM | 6.5 | 0.5% | Jun 28, 2024 | The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which c... |
| CVE-2024-39352 | MEDIUM | 4.9 | 0.9% | Jun 28, 2024 | A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote aut... |
| CVE-2024-30109 | MEDIUM | 6.1 | 0.4% | Jun 28, 2024 | HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multipl... |
| CVE-2024-6296 | MEDIUM | 6.4 | 0.5% | Jun 28, 2024 | The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-5864 | MEDIUM | 4.3 | 0.4% | Jun 28, 2024 | The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-5863 | MEDIUM | 5.4 | 0.5% | Jun 28, 2024 | The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now