2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-35728 | MEDIUM | 5.3 | 0.3% | Jun 10, 2024 | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Them... |
| CVE-2024-35712 | MEDIUM | 4.9 | 0.6% | Jun 10, 2024 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Clea... |
| CVE-2024-35680 | MEDIUM | 5.3 | 0.3% | Jun 10, 2024 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce... |
| CVE-2024-35474 | MEDIUM | 6.5 | 0.9% | Jun 10, 2024 | A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose ... |
| CVE-2024-31613 | MEDIUM | 5.4 | 0.2% | Jun 10, 2024 | BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." |
| CVE-2024-36531 | MEDIUM | 5.7 | 0.4% | Jun 10, 2024 | nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admi... |
| CVE-2024-36406 | MEDIUM | 5.4 | 0.3% | Jun 10, 2024 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ... |
| CVE-2024-5786 | MEDIUM | 6.5 | 0.2% | Jun 10, 2024 | Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This... |
| CVE-2024-4746 | MEDIUM | 6.3 | 0.2% | Jun 10, 2024 | Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Secu... |
| CVE-2024-4745 | MEDIUM | 6.3 | 0.3% | Jun 10, 2024 | Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways an... |
| CVE-2024-2408 | MEDIUM | 5.9 | 1.2% | Jun 9, 2024 | The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is ... |
| CVE-2024-5458 | MEDIUM | 5.3 | 12.1% | Jun 9, 2024 | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering funct... |
| CVE-2024-35748 | MEDIUM | 5.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in OPMC WooCommerce Dropshipping.This issue affects WooCommerce Dropshipping: from n... |
| CVE-2024-32704 | MEDIUM | 6.5 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=... |
| CVE-2024-31347 | MEDIUM | 4.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a ... |
| CVE-2024-31307 | MEDIUM | 6.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: ... |
| CVE-2024-32725 | MEDIUM | 5.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue a... |
| CVE-2024-37535 | MEDIUM | 4.4 | 0.2% | Jun 9, 2024 | GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape ... |
| CVE-2024-32727 | MEDIUM | 5.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in Rometheme RomethemeForm For Elementor.This issue affects RomethemeForm For Elemen... |
| CVE-2024-32821 | MEDIUM | 4.3 | 0.4% | Jun 9, 2024 | Missing Authorization vulnerability in TotalSuite Total Poll Lite.This issue affects Total Poll Lite: from n/a through 4... |
| CVE-2024-32820 | MEDIUM | 5.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Soc... |
| CVE-2024-32814 | MEDIUM | 5.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pic... |
| CVE-2024-32813 | MEDIUM | 5.3 | 0.3% | Jun 9, 2024 | Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/... |
| CVE-2024-32811 | MEDIUM | 5.3 | 0.4% | Jun 9, 2024 | Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.Th... |
| CVE-2024-32805 | MEDIUM | 6.5 | 0.4% | Jun 9, 2024 | Missing Authorization vulnerability in Social Snap.This issue affects Social Snap: from n/a through 1.3.5. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now