2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4450 | MEDIUM | 6.3 | 0.3% | Jun 19, 2024 | The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing... |
| CVE-2024-3984 | MEDIUM | 6.4 | 0.3% | Jun 19, 2024 | The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2024-5970 | MEDIUM | 6.4 | 0.3% | Jun 18, 2024 | The MaxGalleria plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's maxgallery_thumb shor... |
| CVE-2024-6128 | MEDIUM | 5.3 | 0.5% | Jun 18, 2024 | A vulnerability, which was classified as problematic, has been found in spa-cartcms 1.9.0.6. This issue affects some unk... |
| CVE-2024-38277 | MEDIUM | 5.4 | 0.2% | Jun 18, 2024 | A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used inte... |
| CVE-2024-38274 | MEDIUM | 6.1 | 0.4% | Jun 18, 2024 | Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt. |
| CVE-2024-38273 | MEDIUM | 5.4 | 0.4% | Jun 18, 2024 | Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not ha... |
| CVE-2024-36977 | MEDIUM | 5.5 | 0.2% | Jun 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: Wait unconditionally after issuing EndXf... |
| CVE-2024-36976 | MEDIUM | 5.5 | 0.1% | Jun 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls ... |
| CVE-2024-36975 | MEDIUM | 5.5 | 0.2% | Jun 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Do not use WARN when encode fails W... |
| CVE-2024-37791 | MEDIUM | 6 | 0.6% | Jun 18, 2024 | DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/ind... |
| CVE-2024-38351 | MEDIUM | 5.4 | 0.3% | Jun 18, 2024 | Pocketbase is an open source web backend written in go. In affected versions a malicious user may be able to compromise ... |
| CVE-2024-37904 | MEDIUM | 5.7 | 0.5% | Jun 18, 2024 | Minder is an open source Software Supply Chain Security Platform. Minder's Git provider is vulnerable to a denial of ser... |
| CVE-2024-37803 | MEDIUM | 5.4 | 0.3% | Jun 18, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 a... |
| CVE-2024-37800 | MEDIUM | 6.1 | 0.3% | Jun 18, 2024 | CodeProjects Restaurant Reservation System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnera... |
| CVE-2024-37799 | MEDIUM | 5.4 | 0.3% | Jun 18, 2024 | CodeProjects Restaurant Reservation System v1.0 was discovered to contain a SQL injection vulnerability via the reserv_i... |
| CVE-2024-21685 | MEDIUM | 6.5 | 0.4% | Jun 18, 2024 | This High severity Information Disclosure vulnerability was introduced in versions 9.4.0, 9.12.0, and 9.15.0 of Jira Cor... |
| CVE-2024-38507 | MEDIUM | 5.4 | 0.2% | Jun 18, 2024 | In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible |
| CVE-2024-38504 | MEDIUM | 5.3 | 0.4% | Jun 18, 2024 | In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles |
| CVE-2024-6108 | MEDIUM | 6.9 | 0.4% | Jun 18, 2024 | A vulnerability was found in Genexis Tilgin Home Gateway 322_AS0500-03_05_13_05. It has been classified as problematic. ... |
| CVE-2024-5953 | MEDIUM | 5.7 | 0.6% | Jun 18, 2024 | A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user t... |
| CVE-2024-5533 | MEDIUM | 5.4 | 0.3% | Jun 18, 2024 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.25.1 d... |
| CVE-2024-5172 | MEDIUM | 4.8 | 0.4% | Jun 18, 2024 | The Expert Invoice WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow h... |
| CVE-2024-4094 | MEDIUM | 5.4 | 0.4% | Jun 18, 2024 | The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which co... |
| CVE-2024-3276 | MEDIUM | 4.8 | 0.3% | Jun 18, 2024 | The Lightbox & Modal Popup WordPress Plugin WordPress plugin before 2.7.28, foobox-image-lightbox-premium WordPress plu... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now