2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-36656 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (... |
| CVE-2024-23442 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th... |
| CVE-2024-5731 | MEDIUM | 6.8 | 0.3% | Jun 14, 2024 | A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to cont... |
| CVE-2024-2023 | MEDIUM | 4.3 | 0.7% | Jun 14, 2024 | The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi... |
| CVE-2024-34012 | MEDIUM | 4.4 | 0.1% | Jun 14, 2024 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage... |
| CVE-2024-4863 | MEDIUM | 5.4 | 0.5% | Jun 14, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si... |
| CVE-2024-37182 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows ... |
| CVE-2024-25142 | MEDIUM | 5.5 | 0.3% | Jun 14, 2024 | Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cac... |
| CVE-2024-5961 | MEDIUM | 5.3 | 1.3% | Jun 14, 2024 | Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cros... |
| CVE-2024-5465 | MEDIUM | 5.5 | 0.1% | Jun 14, 2024 | Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availa... |
| CVE-2024-36503 | MEDIUM | 5.5 | 0.1% | Jun 14, 2024 | Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect ... |
| CVE-2024-36502 | MEDIUM | 5.5 | 0.1% | Jun 14, 2024 | Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect a... |
| CVE-2024-36501 | MEDIUM | 5.5 | 0.1% | Jun 14, 2024 | Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect ... |
| CVE-2024-36500 | MEDIUM | 5.5 | 0.1% | Jun 14, 2024 | Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect se... |
| CVE-2024-36499 | MEDIUM | 5.5 | 0.1% | Jun 14, 2024 | Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerabili... |
| CVE-2024-5994 | MEDIUM | 5.4 | 0.4% | Jun 14, 2024 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS... |
| CVE-2024-5155 | MEDIUM | 6.1 | 0.2% | Jun 14, 2024 | The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as ... |
| CVE-2024-4751 | MEDIUM | 4.3 | 0.2% | Jun 14, 2024 | The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which coul... |
| CVE-2024-4480 | MEDIUM | 6.1 | 0.2% | Jun 14, 2024 | The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, whic... |
| CVE-2024-4271 | MEDIUM | 4.6 | 0.3% | Jun 14, 2024 | The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the a... |
| CVE-2024-4270 | MEDIUM | 5.4 | 0.3% | Jun 14, 2024 | The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the aut... |
| CVE-2024-4005 | MEDIUM | 4.8 | 0.4% | Jun 14, 2024 | The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-3993 | MEDIUM | 4.6 | 0.2% | Jun 14, 2024 | The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as wel... |
| CVE-2024-3992 | MEDIUM | 4.8 | 0.4% | Jun 14, 2024 | The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privil... |
| CVE-2024-3978 | MEDIUM | 5.4 | 0.4% | Jun 14, 2024 | The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now