2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38271 | MEDIUM | 4.8 | 0.2% | Jun 26, 2024 | There exists a vulnerability in Quick Share/Nearby, where an attacker can force a victim to stay connected to a temporar... |
| CVE-2024-25637 | MEDIUM | 5.4 | 0.3% | Jun 26, 2024 | October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not ... |
| CVE-2024-4604 | MEDIUM | 6.1 | 0.2% | Jun 26, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Magarsus Consultancy SSO (Single Sign On) allows Ma... |
| CVE-2024-5215 | MEDIUM | 5.4 | 0.4% | Jun 26, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multip... |
| CVE-2024-5573 | MEDIUM | 5.9 | 0.3% | Jun 26, 2024 | The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could... |
| CVE-2024-5473 | MEDIUM | 4 | 0.3% | Jun 26, 2024 | The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-5332 | MEDIUM | 5.4 | 0.3% | Jun 26, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca... |
| CVE-2024-5199 | MEDIUM | 5.4 | 0.4% | Jun 26, 2024 | The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes befor... |
| CVE-2024-5169 | MEDIUM | 4.8 | 0.4% | Jun 26, 2024 | The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-5071 | MEDIUM | 6.5 | 0.4% | Jun 26, 2024 | The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing at... |
| CVE-2024-4959 | MEDIUM | 4.8 | 0.3% | Jun 26, 2024 | The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-4957 | MEDIUM | 4.3 | 0.3% | Jun 26, 2024 | The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-4106 | MEDIUM | 5.3 | 0.4% | Jun 26, 2024 | A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor... |
| CVE-2024-4105 | MEDIUM | 5.8 | 0.5% | Jun 26, 2024 | A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process ... |
| CVE-2024-3633 | MEDIUM | 5.4 | 0.3% | Jun 26, 2024 | The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with... |
| CVE-2024-34580 | MEDIUM | 5.3 | 0.2% | Jun 26, 2024 | Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification wit... |
| CVE-2024-21520 | MEDIUM | 6.1 | 1.1% | Jun 26, 2024 | Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_lon... |
| CVE-2024-37139 | MEDIUM | 6.5 | 0.5% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a ... |
| CVE-2024-37138 | MEDIUM | 6.8 | 0.4% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path t... |
| CVE-2024-27867 | MEDIUM | 4.3 | 0.8% | Jun 26, 2024 | An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A3... |
| CVE-2024-29175 | MEDIUM | 5.9 | 0.3% | Jun 26, 2024 | Dell PowerProtect Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.40, LTS 7.10.1.30 contain an weak cryptographic alg... |
| CVE-2024-29174 | MEDIUM | 4.4 | 0.2% | Jun 26, 2024 | Dell Data Domain, versions prior to 7.13.0.0, LTS 7.7.5.30, LTS 7.10.1.20 contain an SQL Injection vulnerability. A loca... |
| CVE-2024-29173 | MEDIUM | 4.9 | 0.3% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Server-Side Request For... |
| CVE-2024-28973 | MEDIUM | 4.8 | 0.2% | Jun 26, 2024 | Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a Stored Cross-Site Scrip... |
| CVE-2024-5173 | MEDIUM | 5.4 | 0.3% | Jun 26, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Vi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now