2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4274 | MEDIUM | 4.3 | 0.5% | Jun 4, 2024 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation... |
| CVE-2024-4273 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_proper... |
| CVE-2024-4057 | MEDIUM | 6.1 | 0.4% | Jun 4, 2024 | The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its bloc... |
| CVE-2024-3230 | MEDIUM | 6.4 | 0.3% | Jun 4, 2024 | The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-at... |
| CVE-2024-3031 | MEDIUM | 4.4 | 0.3% | Jun 4, 2024 | The Fluid Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2024-2470 | MEDIUM | 5.4 | 0.3% | Jun 4, 2024 | The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-2382 | MEDIUM | 5.3 | 0.2% | Jun 4, 2024 | The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions u... |
| CVE-2024-1718 | MEDIUM | 5.3 | 0.2% | Jun 4, 2024 | The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ... |
| CVE-2024-1717 | MEDIUM | 4.3 | 0.4% | Jun 4, 2024 | The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2024-0757 | MEDIUM | 5.4 | 0.9% | Jun 4, 2024 | The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file e... |
| CVE-2024-3888 | MEDIUM | 6.4 | 0.3% | Jun 4, 2024 | The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode ... |
| CVE-2024-29976 | MEDIUM | 6.5 | 9.0% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyx... |
| CVE-2024-29975 | MEDIUM | 6.7 | 0.5% | Jun 4, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel N... |
| CVE-2024-34051 | MEDIUM | 4.6 | 12.0% | Jun 3, 2024 | A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.... |
| CVE-2024-36674 | MEDIUM | 6.1 | 0.3% | Jun 3, 2024 | LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php. |
| CVE-2024-36124 | MEDIUM | 5.3 | 0.5% | Jun 3, 2024 | iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bo... |
| CVE-2024-36123 | MEDIUM | 5.4 | 0.5% | Jun 3, 2024 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its ... |
| CVE-2024-36729 | MEDIUM | 6.3 | 5.0% | Jun 3, 2024 | TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows... |
| CVE-2024-35632 | MEDIUM | 4.3 | 0.2% | Jun 3, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This i... |
| CVE-2024-34770 | MEDIUM | 6.5 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup ... |
| CVE-2024-34769 | MEDIUM | 6.5 | 0.2% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in cyclonethem... |
| CVE-2024-34767 | MEDIUM | 5.4 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes S... |
| CVE-2024-34766 | MEDIUM | 6.5 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ... |
| CVE-2024-34385 | MEDIUM | 5.9 | 0.3% | Jun 3, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooC... |
| CVE-2024-34803 | MEDIUM | 4.3 | 0.3% | Jun 3, 2024 | Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now