2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-34570 | MEDIUM | 4.8 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elemento... |
| CVE-2024-34569 | MEDIUM | 6.5 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Zotpress zot... |
| CVE-2024-34568 | MEDIUM | 5.9 | 0.2% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeqx LetterPres... |
| CVE-2024-34566 | MEDIUM | 5.4 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk... |
| CVE-2024-34565 | MEDIUM | 5.9 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debug Info allows ... |
| CVE-2024-34564 | MEDIUM | 6.5 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Inc. Cou... |
| CVE-2024-34563 | MEDIUM | 6.5 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoldAddons Gold Ad... |
| CVE-2024-34562 | MEDIUM | 5.4 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Ad... |
| CVE-2024-4281 | MEDIUM | 5.4 | 0.3% | May 8, 2024 | The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' short... |
| CVE-2024-4135 | MEDIUM | 5.4 | 0.4% | May 8, 2024 | The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inclu... |
| CVE-2024-34572 | MEDIUM | 6.5 | 0.2% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePrix Fancy El... |
| CVE-2024-34571 | MEDIUM | 6.5 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalay... |
| CVE-2024-34574 | MEDIUM | 5.9 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker... |
| CVE-2024-34573 | MEDIUM | 6.5 | 0.3% | May 8, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pootlepress Pootle... |
| CVE-2024-3494 | MEDIUM | 6.4 | 0.3% | May 8, 2024 | The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_co... |
| CVE-2024-1076 | MEDIUM | 6.5 | 0.4% | May 8, 2024 | The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it... |
| CVE-2024-32674 | MEDIUM | 5.4 | 0.3% | May 8, 2024 | Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is e... |
| CVE-2024-22266 | MEDIUM | 6.5 | 0.4% | May 8, 2024 | VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system ... |
| CVE-2024-4418 | MEDIUM | 6.2 | 0.5% | May 8, 2024 | A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClien... |
| CVE-2024-4162 | MEDIUM | 4.4 | 0.2% | May 8, 2024 | A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory. |
| CVE-2024-1930 | MEDIUM | 6.5 | 0.3% | May 8, 2024 | No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious... |
| CVE-2024-4456 | MEDIUM | 5.4 | 0.3% | May 8, 2024 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payloa... |
| CVE-2024-23551 | MEDIUM | 6.5 | 0.2% | May 7, 2024 | Database scanning using username and password stores the credentials in plaintext or encoded format within files at the ... |
| CVE-2024-23712 | MEDIUM | 5.5 | 0.1% | May 7, 2024 | In multiple functions of AppOpsService.java, there is a possible way to saturate the content of /data/system/appops_acce... |
| CVE-2024-23709 | MEDIUM | 6.5 | 0.8% | May 7, 2024 | In multiple locations, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now