2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36270 | MEDIUM | 5.5 | 0.3% | Jun 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: netfilter: tproxy: bail out if IP has been disabled... |
| CVE-2024-36244 | MEDIUM | 5.5 | 0.2% | Jun 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: net/sched: taprio: extend minimum interval restrict... |
| CVE-2024-33621 | MEDIUM | 5.5 | 0.3% | Jun 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_o... |
| CVE-2024-33619 | MEDIUM | 5.5 | 0.2% | Jun 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when alloc... |
| CVE-2024-31076 | MEDIUM | 5.5 | 0.3% | Jun 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: genirq/cpuhotplug, x86/vector: Prevent vector leak ... |
| CVE-2024-5859 | MEDIUM | 6.1 | 0.3% | Jun 21, 2024 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Reflected Cross-Si... |
| CVE-2024-6225 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-5945 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | The WP SVG Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘type’ parameter in all vers... |
| CVE-2024-5639 | MEDIUM | 4.3 | 0.4% | Jun 21, 2024 | The User Profile Picture plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a... |
| CVE-2024-5191 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-38874 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing acc... |
| CVE-2024-38873 | MEDIUM | 5.3 | 0.5% | Jun 21, 2024 | An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for... |
| CVE-2024-5448 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not validate and esca... |
| CVE-2024-5447 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode WordPress plugin through 1.7 does not sanitise and esca... |
| CVE-2024-4970 | MEDIUM | 4.8 | 0.4% | Jun 21, 2024 | The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow hi... |
| CVE-2024-4969 | MEDIUM | 4.3 | 0.2% | Jun 21, 2024 | The Widget Bundle WordPress plugin through 2.0.0 does not have CSRF checks when logging Widgets, which could allow attac... |
| CVE-2024-4755 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | The Google CSE WordPress plugin through 1.0.7 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-4616 | MEDIUM | 6.1 | 0.4% | Jun 21, 2024 | The Widget Bundle WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back in t... |
| CVE-2024-4477 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | The WP Logs Book WordPress plugin through 1.0.1 does not sanitise and escape some of its log data before outputting them... |
| CVE-2024-4475 | MEDIUM | 4.3 | 0.2% | Jun 21, 2024 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check when clearing logs, which could allow attackers... |
| CVE-2024-4474 | MEDIUM | 4.3 | 6.0% | Jun 21, 2024 | The WP Logs Book WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, which coul... |
| CVE-2024-4384 | MEDIUM | 4.8 | 0.4% | Jun 21, 2024 | The CSSable Countdown WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow ... |
| CVE-2024-4382 | MEDIUM | 6.5 | 0.2% | Jun 21, 2024 | The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow atta... |
| CVE-2024-4381 | MEDIUM | 4.8 | 0.3% | Jun 21, 2024 | The CB (legacy) WordPress plugin through 0.9.4.18 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-4377 | MEDIUM | 5.4 | 0.3% | Jun 21, 2024 | The DOP Shortcodes WordPress plugin through 1.2 does not validate and escape some of its shortcode attributes before out... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now