2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34071 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirec... |
| CVE-2024-35180 | MEDIUM | 6.1 | 0.3% | May 21, 2024 | OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `ca... |
| CVE-2024-3268 | MEDIUM | 5.3 | 0.3% | May 21, 2024 | The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to... |
| CVE-2024-4876 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p... |
| CVE-2024-4619 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cro... |
| CVE-2024-4361 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteo... |
| CVE-2024-4700 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2024-4695 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in ... |
| CVE-2024-4553 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-4875 | MEDIUM | 4.3 | 0.8% | May 21, 2024 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss... |
| CVE-2024-3345 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortc... |
| CVE-2024-4710 | MEDIUM | 6.4 | 0.3% | May 21, 2024 | The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_m... |
| CVE-2024-4470 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2024-4372 | MEDIUM | 5.4 | 0.4% | May 21, 2024 | The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users... |
| CVE-2024-4289 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting ... |
| CVE-2024-4061 | MEDIUM | 4.8 | 0.4% | May 21, 2024 | The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-2189 | MEDIUM | 6.1 | 0.4% | May 21, 2024 | The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget... |
| CVE-2024-4943 | MEDIUM | 5.4 | 0.3% | May 21, 2024 | The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in a... |
| CVE-2024-3155 | MEDIUM | 6.4 | 0.3% | May 21, 2024 | The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre... |
| CVE-2024-0816 | MEDIUM | 5.5 | 0.1% | May 21, 2024 | The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local a... |
| CVE-2024-35195 | MEDIUM | 5.6 | 0.3% | May 20, 2024 | Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is ... |
| CVE-2024-35194 | MEDIUM | 5.3 | 0.4% | May 20, 2024 | Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial o... |
| CVE-2024-35192 | MEDIUM | 5.5 | 0.2% | May 20, 2024 | Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images fro... |
| CVE-2024-35191 | MEDIUM | 4.4 | 0.3% | May 20, 2024 | Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include mali... |
| CVE-2024-33901 | MEDIUM | 6.5 | 0.7% | May 20, 2024 | Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now