2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4087 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-3565 | MEDIUM | 5.4 | 0.3% | Jun 1, 2024 | The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-4711 | MEDIUM | 5.4 | 0.4% | Jun 1, 2024 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-2933 | MEDIUM | 6.4 | 0.3% | Jun 1, 2024 | The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the S... |
| CVE-2024-34006 | MEDIUM | 4.3 | 0.4% | May 31, 2024 | The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in... |
| CVE-2024-34005 | MEDIUM | 6.5 | 0.5% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-34004 | MEDIUM | 6.5 | 0.5% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-34003 | MEDIUM | 5.9 | 0.4% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-34002 | MEDIUM | 6.5 | 0.5% | May 31, 2024 | In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ... |
| CVE-2024-36845 | MEDIUM | 4.3 | 0.5% | May 31, 2024 | An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (D... |
| CVE-2024-34000 | MEDIUM | 4.3 | 0.5% | May 31, 2024 | ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk. |
| CVE-2024-33998 | MEDIUM | 5.4 | 0.4% | May 31, 2024 | Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacti... |
| CVE-2024-33997 | MEDIUM | 6.1 | 0.4% | May 31, 2024 | Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another us... |
| CVE-2024-33996 | MEDIUM | 6.2 | 0.4% | May 31, 2024 | Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events w... |
| CVE-2024-22060 | MEDIUM | 4.9 | 1.1% | May 31, 2024 | An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, hi... |
| CVE-2024-31908 | MEDIUM | 5.4 | 0.2% | May 31, 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users t... |
| CVE-2024-31907 | MEDIUM | 5.4 | 0.2% | May 31, 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2024-31889 | MEDIUM | 5.4 | 0.2% | May 31, 2024 | IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed... |
| CVE-2024-22338 | MEDIUM | 5.5 | 0.2% | May 31, 2024 | IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to... |
| CVE-2024-5347 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribu... |
| CVE-2024-5041 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-... |
| CVE-2024-4160 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packag... |
| CVE-2024-5524 | MEDIUM | 5.3 | 0.3% | May 31, 2024 | Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered us... |
| CVE-2024-5427 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is v... |
| CVE-2024-4379 | MEDIUM | 5.4 | 0.3% | May 31, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Glob... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now