2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-5096 | MEDIUM | 6.9 | 0.6% | May 19, 2024 | A vulnerability classified as problematic was found in Hipcam Device up to 20240511. This vulnerability affects unknown ... |
| CVE-2024-36050 | MEDIUM | 4.3 | 0.4% | May 18, 2024 | Nix through 2.22.1 mishandles certain usage of hash caches, which makes it easier for attackers to replace current sourc... |
| CVE-2024-28063 | MEDIUM | 6.1 | 0.3% | May 18, 2024 | Kiteworks Totemomail through 7.0.0 allows /responsiveUI/EnvelopeOpenServlet envelopeRecipient reflected XSS. |
| CVE-2024-36043 | MEDIUM | 6.1 | 0.3% | May 18, 2024 | question_image.ts in SurveyJS Form Library before 1.10.4 allows contentMode=youtube XSS via the imageLink property. |
| CVE-2024-34083 | MEDIUM | 5.4 | 0.2% | May 18, 2024 | aiosmptd is a reimplementation of the Python stdlib smtpd.py based on asyncio. Prior to version 1.4.6, servers based on... |
| CVE-2024-5088 | MEDIUM | 5.4 | 0.4% | May 18, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter... |
| CVE-2024-4432 | MEDIUM | 6.4 | 0.3% | May 18, 2024 | The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg... |
| CVE-2024-4709 | MEDIUM | 6.4 | 0.4% | May 18, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-4698 | MEDIUM | 6.4 | 0.4% | May 18, 2024 | The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'show_l... |
| CVE-2024-2772 | MEDIUM | 5.4 | 0.3% | May 18, 2024 | The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulner... |
| CVE-2024-4849 | MEDIUM | 6.4 | 0.3% | May 18, 2024 | The WordPress Automatic Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘autoplay’ para... |
| CVE-2024-3811 | MEDIUM | 6.4 | 0.3% | May 18, 2024 | The Salient Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'icon' shortco... |
| CVE-2024-4891 | MEDIUM | 5.4 | 0.5% | May 18, 2024 | The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ... |
| CVE-2024-4374 | MEDIUM | 5.4 | 0.4% | May 18, 2024 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets ... |
| CVE-2024-3714 | MEDIUM | 5.4 | 0.3% | May 18, 2024 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2024-4865 | MEDIUM | 5.4 | 0.4% | May 18, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter... |
| CVE-2024-23583 | MEDIUM | 6.7 | 0.2% | May 17, 2024 | An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client D... |
| CVE-2024-35312 | MEDIUM | 6.2 | 0.2% | May 17, 2024 | In Tor Arti before 1.2.3, STUB circuits incorrectly have a length of 2 (with lite vanguards), aka TROVE-2024-003. |
| CVE-2024-25742 | MEDIUM | 6.5 | 0.2% | May 17, 2024 | In the Linux kernel before 6.9, an untrusted hypervisor can inject virtual interrupt 29 (#VC) at any point in time and c... |
| CVE-2024-34959 | MEDIUM | 5.5 | 0.3% | May 17, 2024 | DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php. |
| CVE-2024-5022 | MEDIUM | 4.4 | 0.1% | May 17, 2024 | The file scheme of URLs would be hidden, resulting in potential spoofing of a website's address in the location bar This... |
| CVE-2024-35190 | MEDIUM | 5.3 | 0.6% | May 17, 2024 | Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP... |
| CVE-2024-5072 | MEDIUM | 6.5 | 0.7% | May 17, 2024 | Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authentic... |
| CVE-2024-34241 | MEDIUM | 4.8 | 0.8% | May 17, 2024 | A cross-site scripting (XSS) vulnerability in Rocketsoft Rocket LMS 1.9 allows an administrator to store a JavaScript pa... |
| CVE-2024-31974 | MEDIUM | 6.3 | 0.6% | May 17, 2024 | The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now