2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4942 | MEDIUM | 4.8 | 0.3% | Jun 6, 2024 | The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2024-4788 | MEDIUM | 4.3 | 0.3% | Jun 6, 2024 | The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2024-4705 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials ... |
| CVE-2024-2350 | MEDIUM | 5.4 | 0.3% | Jun 6, 2024 | The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAF... |
| CVE-2024-0910 | MEDIUM | 5.3 | 0.5% | Jun 6, 2024 | The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a... |
| CVE-2024-0912 | MEDIUM | 4.2 | 0.2% | Jun 6, 2024 | Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server wil... |
| CVE-2024-27381 | MEDIUM | 6 | 0.2% | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I... |
| CVE-2024-27380 | MEDIUM | 6 | 0.2% | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I... |
| CVE-2024-20405 | MEDIUM | 6.1 | 0.6% | Jun 5, 2024 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t... |
| CVE-2024-20404 | MEDIUM | 5.3 | 23.1% | Jun 5, 2024 | A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t... |
| CVE-2024-24789 | MEDIUM | 5.5 | 0.4% | Jun 5, 2024 | The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implement... |
| CVE-2024-4812 | MEDIUM | 4.8 | 0.3% | Jun 5, 2024 | A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Desc... |
| CVE-2024-3716 | MEDIUM | 6.2 | 0.2% | Jun 5, 2024 | A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue le... |
| CVE-2024-35673 | MEDIUM | 4.3 | 0.2% | Jun 5, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a th... |
| CVE-2024-5459 | MEDIUM | 4.3 | 0.4% | Jun 5, 2024 | The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missi... |
| CVE-2024-3469 | MEDIUM | 6.1 | 0.6% | Jun 5, 2024 | The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all ver... |
| CVE-2024-4001 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_logi... |
| CVE-2024-5536 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link s... |
| CVE-2024-5571 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute... |
| CVE-2024-4821 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-5453 | MEDIUM | 4.3 | 0.4% | Jun 5, 2024 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2024-5439 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all vers... |
| CVE-2024-5006 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2024-4939 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div s... |
| CVE-2024-5222 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for Wo... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now