2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5310 | MEDIUM | 5.4 | 0.4% | May 24, 2024 | A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of th... |
| CVE-2024-4366 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bloc... |
| CVE-2024-5060 | MEDIUM | 5.4 | 0.4% | May 24, 2024 | The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2024-4485 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-4484 | MEDIUM | 5.4 | 0.7% | May 24, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-1376 | MEDIUM | 4.3 | 0.3% | May 24, 2024 | The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check... |
| CVE-2024-1332 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg fil... |
| CVE-2024-0893 | MEDIUM | 4.3 | 0.3% | May 24, 2024 | The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ... |
| CVE-2024-5142 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticat... |
| CVE-2024-3718 | MEDIUM | 5.4 | 0.4% | May 24, 2024 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the p... |
| CVE-2024-36361 | MEDIUM | 6.8 | 0.5% | May 24, 2024 | Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the ... |
| CVE-2024-1134 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and descr... |
| CVE-2024-3557 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-2784 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card w... |
| CVE-2024-2618 | MEDIUM | 5.4 | 0.3% | May 24, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size att... |
| CVE-2024-5205 | MEDIUM | 6.4 | 0.3% | May 24, 2024 | The Videojs HTML5 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videojs_vide... |
| CVE-2024-4409 | MEDIUM | 4.3 | 0.2% | May 24, 2024 | The WP-ViperGB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2024-5279 | MEDIUM | 5.3 | 0.3% | May 23, 2024 | A vulnerability was found in Qiwen Netdisk up to 1.4.0. It has been declared as problematic. Affected by this vulnerabil... |
| CVE-2024-5294 | MEDIUM | 6.5 | 0.5% | May 23, 2024 | D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows netw... |
| CVE-2024-5244 | MEDIUM | 4.2 | 0.3% | May 23, 2024 | TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent att... |
| CVE-2024-31843 | MEDIUM | 4.1 | 0.5% | May 23, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as inp... |
| CVE-2024-5143 | MEDIUM | 6.8 | 0.4% | May 23, 2024 | A user with device administrative privileges can change existing SMTP server settings on the device, without having to r... |
| CVE-2024-4365 | MEDIUM | 6.4 | 0.3% | May 23, 2024 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_d... |
| CVE-2024-35085 | MEDIUM | 5.4 | 0.2% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMa... |
| CVE-2024-35082 | MEDIUM | 6.3 | 0.3% | May 23, 2024 | J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xm... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now