2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6183 | MEDIUM | 6.1 | 0.4% | Jun 20, 2024 | A vulnerability classified as problematic has been found in EZ-Suite EZ-Partner 5. Affected is an unknown function of th... |
| CVE-2024-6182 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown pro... |
| CVE-2024-6181 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unkno... |
| CVE-2024-5036 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-34693 | MEDIUM | 5.3 | 1.6% | Jun 20, 2024 | Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB con... |
| CVE-2024-29013 | MEDIUM | 6.5 | 0.6% | Jun 20, 2024 | Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial ... |
| CVE-2024-38620 | MEDIUM | 5.5 | 0.3% | Jun 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS... |
| CVE-2024-38619 | MEDIUM | 5.5 | 0.3% | Jun 20, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is ini... |
| CVE-2024-5522 | MEDIUM | 6.5 | 2.6% | Jun 20, 2024 | The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before... |
| CVE-2024-5475 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes b... |
| CVE-2024-4565 | MEDIUM | 6.5 | 0.4% | Jun 20, 2024 | The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 all... |
| CVE-2024-5686 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2024-4390 | MEDIUM | 6.5 | 0.5% | Jun 20, 2024 | The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi... |
| CVE-2024-5213 | MEDIUM | 6.5 | 0.5% | Jun 20, 2024 | In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a u... |
| CVE-2024-6179 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics Sup... |
| CVE-2024-6178 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics Sup... |
| CVE-2024-6177 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electron... |
| CVE-2024-4742 | MEDIUM | 6.5 | 0.5% | Jun 20, 2024 | The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ... |
| CVE-2024-4626 | MEDIUM | 5.4 | 0.3% | Jun 20, 2024 | The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and... |
| CVE-2024-3627 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2024-3602 | MEDIUM | 4.3 | 0.3% | Jun 20, 2024 | The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPre... |
| CVE-2024-3597 | MEDIUM | 6.1 | 0.3% | Jun 20, 2024 | The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc... |
| CVE-2024-3558 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' p... |
| CVE-2024-1168 | MEDIUM | 5.4 | 0.4% | Jun 20, 2024 | The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social ima... |
| CVE-2024-6176 | MEDIUM | 4.8 | 0.2% | Jun 20, 2024 | Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanni... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now