2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5739 | MEDIUM | 6.1 | 0.3% | Jun 12, 2024 | The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vuln... |
| CVE-2024-28970 | MEDIUM | 4.4 | 0.1% | Jun 12, 2024 | Dell Client BIOS contains an Out-of-bounds Write vulnerability. A local authenticated malicious user with admin privileg... |
| CVE-2024-0160 | MEDIUM | 6.8 | 0.2% | Jun 12, 2024 | Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical access to the system c... |
| CVE-2024-5892 | MEDIUM | 6.4 | 0.3% | Jun 12, 2024 | The Divi Torque Lite – Divi Theme and Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-4924 | MEDIUM | 6.1 | 0.5% | Jun 12, 2024 | The Social Sharing Plugin WordPress plugin before 3.3.63 does not sanitise and escape some of its settings, which could... |
| CVE-2024-36454 | MEDIUM | 5.3 | 0.5% | Jun 12, 2024 | Use of uninitialized resource issue exists in IPCOM EX2 Series (V01L0x Series) V01L07NF0201 and earlier, and IPCOM VE2 S... |
| CVE-2024-0427 | MEDIUM | 6.3 | 0.4% | Jun 12, 2024 | The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.4.1 does not properly escape user-controll... |
| CVE-2024-3559 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_content]'... |
| CVE-2024-5553 | MEDIUM | 5.4 | 0.4% | Jun 12, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via several... |
| CVE-2024-4564 | MEDIUM | 6.4 | 0.4% | Jun 12, 2024 | The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress... |
| CVE-2024-4892 | MEDIUM | 5.4 | 0.3% | Jun 12, 2024 | The BuddyPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘display_name’ parameter in ver... |
| CVE-2024-36103 | MEDIUM | 6.8 | 0.7% | Jun 12, 2024 | OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a... |
| CVE-2024-35225 | MEDIUM | 6.1 | 0.4% | Jun 11, 2024 | Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authen... |
| CVE-2024-5843 | MEDIUM | 6.5 | 0.5% | Jun 11, 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate... |
| CVE-2024-5840 | MEDIUM | 6.5 | 0.4% | Jun 11, 2024 | Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access c... |
| CVE-2024-5839 | MEDIUM | 6.5 | 0.5% | Jun 11, 2024 | Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to po... |
| CVE-2024-5646 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute with... |
| CVE-2024-4669 | MEDIUM | 5.4 | 0.3% | Jun 11, 2024 | The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, U... |
| CVE-2024-34406 | MEDIUM | 5.3 | 0.4% | Jun 11, 2024 | Improper exception handling in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to cause ... |
| CVE-2024-28024 | MEDIUM | 4.1 | 0.1% | Jun 11, 2024 | A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource th... |
| CVE-2024-28022 | MEDIUM | 6.5 | 0.4% | Jun 11, 2024 | A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary... |
| CVE-2024-5851 | MEDIUM | 5.3 | 0.4% | Jun 11, 2024 | A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the ... |
| CVE-2024-36821 | MEDIUM | 6.8 | 2.9% | Jun 11, 2024 | Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest ... |
| CVE-2024-35263 | MEDIUM | 5.7 | 1.7% | Jun 11, 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability |
| CVE-2024-35255 | MEDIUM | 5.5 | 0.8% | Jun 11, 2024 | Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now