2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4088 | MEDIUM | 4.3 | 0.3% | Jun 5, 2024 | The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2024-2368 | MEDIUM | 4.3 | 0.2% | Jun 5, 2024 | The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-1164 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form... |
| CVE-2024-4886 | MEDIUM | 4.3 | 0.4% | Jun 5, 2024 | The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in t... |
| CVE-2024-3667 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of mu... |
| CVE-2024-2087 | MEDIUM | 6.1 | 0.4% | Jun 5, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in a... |
| CVE-2024-1940 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versi... |
| CVE-2024-1161 | MEDIUM | 5.4 | 0.3% | Jun 5, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attri... |
| CVE-2024-5149 | MEDIUM | 5.3 | 0.4% | Jun 5, 2024 | The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8... |
| CVE-2024-34055 | MEDIUM | 6.5 | 0.8% | Jun 5, 2024 | Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation... |
| CVE-2024-5483 | MEDIUM | 5.3 | 1.0% | Jun 5, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio... |
| CVE-2024-5317 | MEDIUM | 6.1 | 0.3% | Jun 5, 2024 | The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions... |
| CVE-2024-30889 | MEDIUM | 5.4 | 0.5% | Jun 4, 2024 | Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execu... |
| CVE-2024-4220 | MEDIUM | 5.3 | 0.3% | Jun 4, 2024 | Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumer... |
| CVE-2024-34364 | MEDIUM | 6.5 | 0.5% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror... |
| CVE-2024-34362 | MEDIUM | 5.9 | 0.6% | Jun 4, 2024 | Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) ... |
| CVE-2024-32464 | MEDIUM | 6.1 | 0.4% | Jun 4, 2024 | Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment includ... |
| CVE-2024-30528 | MEDIUM | 6.3 | 0.3% | Jun 4, 2024 | Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a throu... |
| CVE-2024-34759 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhispe... |
| CVE-2024-35653 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi... |
| CVE-2024-35652 | MEDIUM | 6.1 | 0.3% | Jun 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolo... |
| CVE-2024-35651 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plug... |
| CVE-2024-35649 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pdfcrowd Sa... |
| CVE-2024-29004 | MEDIUM | 4.3 | 0.3% | Jun 4, 2024 | The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web c... |
| CVE-2024-0756 | MEDIUM | 5.4 | 0.2% | Jun 4, 2024 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding i... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now