2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4634 | MEDIUM | 5.4 | 0.4% | May 16, 2024 | The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg... |
| CVE-2024-4617 | MEDIUM | 6.4 | 0.4% | May 16, 2024 | The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ ... |
| CVE-2024-4400 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2024-4385 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up ... |
| CVE-2024-4288 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto... |
| CVE-2024-35302 | MEDIUM | 6.1 | 0.3% | May 16, 2024 | In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible |
| CVE-2024-35301 | MEDIUM | 5.5 | 0.3% | May 16, 2024 | In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token |
| CVE-2024-35300 | MEDIUM | 6.1 | 0.3% | May 16, 2024 | In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible |
| CVE-2024-4975 | MEDIUM | 6.1 | 0.5% | May 16, 2024 | A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue... |
| CVE-2024-4974 | MEDIUM | 6.1 | 0.5% | May 16, 2024 | A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an ... |
| CVE-2024-4968 | MEDIUM | 6.1 | 0.5% | May 16, 2024 | A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected ... |
| CVE-2024-4391 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event ... |
| CVE-2024-4263 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with onl... |
| CVE-2024-3887 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form ... |
| CVE-2024-3851 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper valida... |
| CVE-2024-30309 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ... |
| CVE-2024-30308 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ... |
| CVE-2024-30298 | MEDIUM | 5.5 | 0.3% | May 16, 2024 | Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead ... |
| CVE-2024-30281 | MEDIUM | 5.5 | 0.3% | May 16, 2024 | Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that coul... |
| CVE-2024-20793 | MEDIUM | 5.5 | 0.2% | May 16, 2024 | Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis... |
| CVE-2024-4546 | MEDIUM | 6.4 | 0.3% | May 16, 2024 | The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_... |
| CVE-2024-4478 | MEDIUM | 5.4 | 0.3% | May 16, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Gro... |
| CVE-2024-4843 | MEDIUM | 4.3 | 0.3% | May 16, 2024 | ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow... |
| CVE-2024-4635 | MEDIUM | 6.4 | 0.4% | May 16, 2024 | The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ fu... |
| CVE-2024-4318 | MEDIUM | 6.5 | 0.5% | May 16, 2024 | The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now