2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-21515 | MEDIUM | 4.7 | 0.4% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filenam... |
| CVE-2024-5966 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Grey Opaque theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them... |
| CVE-2024-5965 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's ... |
| CVE-2024-5791 | MEDIUM | 6.1 | 0.3% | Jun 22, 2024 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2024-5346 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Vid... |
| CVE-2024-4313 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter... |
| CVE-2024-2484 | MEDIUM | 5.4 | 0.4% | Jun 22, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post T... |
| CVE-2024-6120 | MEDIUM | 6.5 | 0.5% | Jun 22, 2024 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to ... |
| CVE-2024-37654 | MEDIUM | 6.1 | 0.2% | Jun 21, 2024 | An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD,... |
| CVE-2024-34452 | MEDIUM | 6.1 | 0.7% | Jun 21, 2024 | CMSimple_XH 1.7.6 allows XSS by uploading a crafted SVG document. |
| CVE-2024-37675 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-37673 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-37672 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-37671 | MEDIUM | 5.4 | 0.6% | Jun 21, 2024 | Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute... |
| CVE-2024-35781 | MEDIUM | 6.5 | 0.5% | Jun 21, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in YAHMAN Word Balloon allo... |
| CVE-2024-35768 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LiveComposer Page ... |
| CVE-2024-35766 | MEDIUM | 6.1 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ollybach WP... |
| CVE-2024-35764 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in andy_moyle Church ... |
| CVE-2024-35763 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Frees... |
| CVE-2024-35762 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Cryout Crea... |
| CVE-2024-35761 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita Onlin... |
| CVE-2024-35760 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job... |
| CVE-2024-35759 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpjobportal WP Job... |
| CVE-2024-35758 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Theme Horse... |
| CVE-2024-35757 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in 5 Star Plug... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now