2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38394 | MEDIUM | 4.3 | 0.3% | Jun 16, 2024 | Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kerne... |
| CVE-2024-5611 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ ... |
| CVE-2024-5858 | MEDIUM | 4.3 | 0.3% | Jun 15, 2024 | The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-4095 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'ex... |
| CVE-2024-2695 | MEDIUM | 5.4 | 0.3% | Jun 15, 2024 | The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco... |
| CVE-2024-1399 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-5868 | MEDIUM | 5.3 | 0.3% | Jun 15, 2024 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and inclu... |
| CVE-2024-5263 | MEDIUM | 5.4 | 0.3% | Jun 15, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and T... |
| CVE-2024-4479 | MEDIUM | 5.4 | 0.4% | Jun 15, 2024 | The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_en... |
| CVE-2024-3815 | MEDIUM | 4.8 | 0.3% | Jun 15, 2024 | The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page i... |
| CVE-2024-3814 | MEDIUM | 4.8 | 0.3% | Jun 15, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module i... |
| CVE-2024-2544 | MEDIUM | 6.4 | 0.3% | Jun 15, 2024 | The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss... |
| CVE-2024-21988 | MEDIUM | 5.3 | 0.2% | Jun 14, 2024 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of se... |
| CVE-2024-37889 | MEDIUM | 6.5 | 1.0% | Jun 14, 2024 | MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while sign... |
| CVE-2024-37888 | MEDIUM | 6.1 | 0.9% | Jun 14, 2024 | The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerabili... |
| CVE-2024-36599 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2024-5659 | MEDIUM | 6.5 | 0.3% | Jun 14, 2024 | Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result... |
| CVE-2024-37886 | MEDIUM | 4.7 | 0.2% | Jun 14, 2024 | user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into acceptin... |
| CVE-2024-37884 | MEDIUM | 5.4 | 0.4% | Jun 14, 2024 | Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versi... |
| CVE-2024-37883 | MEDIUM | 4.3 | 0.4% | Jun 14, 2024 | Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra... |
| CVE-2024-37317 | MEDIUM | 4.6 | 0.3% | Jun 14, 2024 | The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder c... |
| CVE-2024-37316 | MEDIUM | 4.6 | 0.4% | Jun 14, 2024 | Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachmen... |
| CVE-2024-37315 | MEDIUM | 4.3 | 0.4% | Jun 14, 2024 | Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore ... |
| CVE-2024-33373 | MEDIUM | 6.3 | 0.3% | Jun 14, 2024 | An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single... |
| CVE-2024-37312 | MEDIUM | 6.3 | 0.6% | Jun 14, 2024 | user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an at... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now