2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3961 | MEDIUM | 5.3 | 0.4% | Jun 21, 2024 | The ConvertKit – Email Newsletter, Email Marketing, Subscribers and Landing Pages plugin for WordPress is vulnerable to ... |
| CVE-2024-5344 | MEDIUM | 6.1 | 0.3% | Jun 21, 2024 | The The Plus Addons for Elementor Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2024-3610 | MEDIUM | 5.3 | 0.5% | Jun 21, 2024 | The WP Child Theme Generator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2024-1955 | MEDIUM | 4.3 | 0.3% | Jun 21, 2024 | The Hide Dashboard Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2024-1639 | MEDIUM | 6.5 | 0.4% | Jun 21, 2024 | The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2024-6212 | MEDIUM | 6.1 | 0.5% | Jun 21, 2024 | A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected... |
| CVE-2024-38361 | MEDIUM | 5.3 | 0.4% | Jun 20, 2024 | Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for custom... |
| CVE-2024-38359 | MEDIUM | 6.5 | 0.6% | Jun 20, 2024 | The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability i... |
| CVE-2024-36071 | MEDIUM | 6.3 | 0.1% | Jun 20, 2024 | Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files u... |
| CVE-2024-31586 | MEDIUM | 6.1 | 0.5% | Jun 20, 2024 | A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerabili... |
| CVE-2024-30848 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject ... |
| CVE-2024-6154 | MEDIUM | 6.7 | 0.3% | Jun 20, 2024 | Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allow... |
| CVE-2024-38093 | MEDIUM | 4.3 | 0.5% | Jun 20, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-38082 | MEDIUM | 4.7 | 0.5% | Jun 20, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
| CVE-2024-37897 | MEDIUM | 5.4 | 0.3% | Jun 20, 2024 | SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azur... |
| CVE-2024-37674 | MEDIUM | 5.5 | 0.6% | Jun 20, 2024 | Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field ... |
| CVE-2024-37350 | MEDIUM | 4.7 | 0.3% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.... |
| CVE-2024-37346 | MEDIUM | 4.9 | 0.4% | Jun 20, 2024 | There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13... |
| CVE-2024-37345 | MEDIUM | 5.4 | 0.2% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to ... |
| CVE-2024-37343 | MEDIUM | 5.4 | 0.2% | Jun 20, 2024 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prio... |
| CVE-2024-33335 | MEDIUM | 6.3 | 0.5% | Jun 20, 2024 | SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code... |
| CVE-2024-28397 | MEDIUM | 5.3 | 4.5% | Jun 20, 2024 | An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a... |
| CVE-2024-37222 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Cross Site Scripting (XSS) vulnerability in Averta Master Slider allows Reflected XSS.This issue affects Master Slider: ... |
| CVE-2024-6188 | MEDIUM | 6.9 | 2.1% | Jun 20, 2024 | A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some un... |
| CVE-2024-5156 | MEDIUM | 6.4 | 0.3% | Jun 20, 2024 | The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versi... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now