2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5640 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ... |
| CVE-2024-5612 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_l... |
| CVE-2024-5425 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in al... |
| CVE-2024-37384 | MEDIUM | 6.1 | 0.5% | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences. |
| CVE-2024-37383 | MEDIUM | 6.1 | 73.3% | Jun 7, 2024 | Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes. |
| CVE-2024-36082 | MEDIUM | 6.5 | 0.5% | Jun 7, 2024 | SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated ... |
| CVE-2024-1988 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre... |
| CVE-2024-5607 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-3987 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2024-1768 | MEDIUM | 5.4 | 0.3% | Jun 7, 2024 | The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all ... |
| CVE-2024-1689 | MEDIUM | 4.3 | 0.3% | Jun 7, 2024 | The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2024-4013 | MEDIUM | 5.6 | 0.3% | Jun 6, 2024 | A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) fr... |
| CVE-2024-36775 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT... |
| CVE-2024-22525 | MEDIUM | 5.5 | 0.2% | Jun 6, 2024 | dnspod-sr 0dfbd37 contains a SEGV. |
| CVE-2024-22524 | MEDIUM | 5.5 | 0.2% | Jun 6, 2024 | dnspod-sr 0dfbd37 is vulnerable to buffer overflow. |
| CVE-2024-36795 | MEDIUM | 4 | 0.3% | Jun 6, 2024 | Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories em... |
| CVE-2024-5550 | MEDIUM | 5.3 | 0.8% | Jun 6, 2024 | In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system pa... |
| CVE-2024-5478 | MEDIUM | 6.1 | 0.3% | Jun 6, 2024 | A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of luna... |
| CVE-2024-5278 | MEDIUM | 6.1 | 0.6% | Jun 6, 2024 | gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of ... |
| CVE-2024-5248 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in ... |
| CVE-2024-5206 | MEDIUM | 4.7 | 0.2% | Jun 6, 2024 | A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to ... |
| CVE-2024-5131 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and includi... |
| CVE-2024-5126 | MEDIUM | 6.5 | 0.3% | Jun 6, 2024 | An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.pat... |
| CVE-2024-4890 | MEDIUM | 4.9 | 0.6% | Jun 6, 2024 | A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' pr... |
| CVE-2024-3404 | MEDIUM | 6.5 | 0.5% | Jun 6, 2024 | In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now