2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4392 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2024-4333 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem... |
| CVE-2024-4144 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all v... |
| CVE-2024-4139 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu... |
| CVE-2024-4138 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu... |
| CVE-2024-3579 | MEDIUM | 6.1 | 0.3% | May 14, 2024 | Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker m... |
| CVE-2024-3374 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to atte... |
| CVE-2024-3241 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputt... |
| CVE-2024-35012 | MEDIUM | 6.3 | 0.2% | May 14, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu... |
| CVE-2024-35011 | MEDIUM | 5.4 | 0.2% | May 14, 2024 | idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu... |
| CVE-2024-34914 | MEDIUM | 5.3 | 0.3% | May 14, 2024 | php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. Th... |
| CVE-2024-34717 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-o... |
| CVE-2024-34716 | MEDIUM | 6.1 | 56.2% | May 14, 2024 | PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects Pr... |
| CVE-2024-34712 | MEDIUM | 6.5 | 0.6% | May 14, 2024 | Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.re... |
| CVE-2024-34358 | MEDIUM | 5.3 | 0.5% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E... |
| CVE-2024-34357 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E... |
| CVE-2024-34356 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E... |
| CVE-2024-34355 | MEDIUM | 5.4 | 0.6% | May 14, 2024 | TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history ba... |
| CVE-2024-34243 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter. |
| CVE-2024-34191 | MEDIUM | 6.5 | 0.5% | May 14, 2024 | htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin.... |
| CVE-2024-33867 | MEDIUM | 4.8 | 0.2% | May 14, 2024 | An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt. |
| CVE-2024-33866 | MEDIUM | 5.5 | 0.4% | May 14, 2024 | An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS. |
| CVE-2024-33864 | MEDIUM | 5.9 | 0.5% | May 14, 2024 | An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via re... |
| CVE-2024-33647 | MEDIUM | 6.5 | 0.4% | May 14, 2024 | A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in th... |
| CVE-2024-33583 | MEDIUM | 4.8 | 0.2% | May 14, 2024 | A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now