2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4980 | MEDIUM | 6.4 | 0.3% | May 22, 2024 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor'... |
| CVE-2024-31396 | MEDIUM | 6.6 | 0.4% | May 22, 2024 | Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series ver... |
| CVE-2024-31395 | MEDIUM | 6.1 | 0.3% | May 22, 2024 | Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ... |
| CVE-2024-31394 | MEDIUM | 6.5 | 0.7% | May 22, 2024 | Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series v... |
| CVE-2024-30420 | MEDIUM | 4.4 | 0.3% | May 22, 2024 | Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and ... |
| CVE-2024-30419 | MEDIUM | 5.4 | 0.2% | May 22, 2024 | Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ... |
| CVE-2024-0451 | MEDIUM | 5 | 0.4% | May 22, 2024 | The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th... |
| CVE-2024-3519 | MEDIUM | 6.1 | 0.3% | May 22, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter ... |
| CVE-2024-3518 | MEDIUM | 6.5 | 0.5% | May 22, 2024 | The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver... |
| CVE-2024-33525 | MEDIUM | 4.3 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational uni... |
| CVE-2024-4154 | MEDIUM | 6.5 | 0.3% | May 21, 2024 | In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projec... |
| CVE-2024-34240 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin func... |
| CVE-2024-22275 | MEDIUM | 4.9 | 1.0% | May 21, 2024 | The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the v... |
| CVE-2024-36039 | MEDIUM | 6.3 | 0.7% | May 21, 2024 | PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict... |
| CVE-2024-31847 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated... |
| CVE-2024-31845 | MEDIUM | 5.3 | 0.4% | May 21, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that... |
| CVE-2024-31844 | MEDIUM | 5.3 | 0.5% | May 21, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases,... |
| CVE-2024-31840 | MEDIUM | 6.5 | 0.4% | May 21, 2024 | An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source cod... |
| CVE-2024-1721 | MEDIUM | 5.6 | 0.1% | May 21, 2024 | Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software... |
| CVE-2024-33528 | MEDIUM | 4.7 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authentic... |
| CVE-2024-33527 | MEDIUM | 5.4 | 0.5% | May 21, 2024 | A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 bef... |
| CVE-2024-4452 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in version... |
| CVE-2024-35385 | MEDIUM | 4.3 | 0.5% | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in ... |
| CVE-2024-35384 | MEDIUM | 5.5 | 0.3% | May 21, 2024 | An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function i... |
| CVE-2024-35218 | MEDIUM | 4.8 | 0.4% | May 21, 2024 | Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers tha... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now