2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3977 | MEDIUM | 4.8 | 0.3% | Jun 14, 2024 | The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-3972 | MEDIUM | 4.3 | 0.2% | Jun 14, 2024 | The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well... |
| CVE-2024-3971 | MEDIUM | 4.3 | 0.2% | Jun 14, 2024 | The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could a... |
| CVE-2024-3966 | MEDIUM | 6.1 | 0.3% | Jun 14, 2024 | The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated... |
| CVE-2024-3965 | MEDIUM | 5.4 | 0.2% | Jun 14, 2024 | The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could... |
| CVE-2024-3754 | MEDIUM | 4.7 | 0.4% | Jun 14, 2024 | The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-2218 | MEDIUM | 4.6 | 0.3% | Jun 14, 2024 | The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which co... |
| CVE-2024-2122 | MEDIUM | 5.4 | 0.5% | Jun 14, 2024 | The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via alb... |
| CVE-2024-23504 | MEDIUM | 5.3 | 0.3% | Jun 14, 2024 | Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through ... |
| CVE-2024-1295 | MEDIUM | 6.5 | 0.5% | Jun 14, 2024 | The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not pr... |
| CVE-2024-5469 | MEDIUM | 4.3 | 0.4% | Jun 14, 2024 | DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an a... |
| CVE-2024-31160 | MEDIUM | 4.8 | 0.3% | Jun 14, 2024 | The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke... |
| CVE-2024-31159 | MEDIUM | 4.8 | 0.3% | Jun 14, 2024 | The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke... |
| CVE-2024-27180 | MEDIUM | 6.7 | 0.3% | Jun 14, 2024 | An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the refe... |
| CVE-2024-27179 | MEDIUM | 4.7 | 0.3% | Jun 14, 2024 | Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. ... |
| CVE-2024-27175 | MEDIUM | 4.4 | 0.9% | Jun 14, 2024 | Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can r... |
| CVE-2024-27163 | MEDIUM | 6.5 | 0.4% | Jun 14, 2024 | Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 speci... |
| CVE-2024-27162 | MEDIUM | 6.1 | 21.2% | Jun 14, 2024 | Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable... |
| CVE-2024-27161 | MEDIUM | 6.2 | 0.2% | Jun 14, 2024 | all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the enc... |
| CVE-2024-27160 | MEDIUM | 6.2 | 0.2% | Jun 14, 2024 | All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt th... |
| CVE-2024-27159 | MEDIUM | 6.2 | 0.3% | Jun 14, 2024 | All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt th... |
| CVE-2024-27157 | MEDIUM | 6.8 | 0.4% | Jun 14, 2024 | The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retr... |
| CVE-2024-27156 | MEDIUM | 6.8 | 0.4% | Jun 14, 2024 | The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication ses... |
| CVE-2024-0892 | MEDIUM | 4.3 | 0.3% | Jun 14, 2024 | The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a... |
| CVE-2024-27154 | MEDIUM | 6.2 | 0.3% | Jun 14, 2024 | Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/version... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now