2024 CVE Vulnerabilities
39,228 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0613 | MEDIUM | 6.1 | 0.2% | May 2, 2024 | The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2024-4433 | MEDIUM | 5.9 | 0.4% | May 2, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple ... |
| CVE-2024-32359 | MEDIUM | 6.9 | 0.2% | May 2, 2024 | An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through design... |
| CVE-2024-31966 | MEDIUM | 6.2 | 0.4% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-31965 | MEDIUM | 4.2 | 0.2% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-31963 | MEDIUM | 6.4 | 0.3% | May 2, 2024 | A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.... |
| CVE-2024-4029 | MEDIUM | 4.1 | 0.3% | May 2, 2024 | A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management... |
| CVE-2024-4128 | MEDIUM | 4.3 | 0.1% | May 2, 2024 | This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint th... |
| CVE-2024-34148 | MEDIUM | 6.8 | 0.8% | May 2, 2024 | Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 ... |
| CVE-2024-34147 | MEDIUM | 4.3 | 0.5% | May 2, 2024 | Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file... |
| CVE-2024-34146 | MEDIUM | 6.5 | 0.5% | May 2, 2024 | Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git re... |
| CVE-2024-34061 | MEDIUM | 4.3 | 1.3% | May 2, 2024 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se... |
| CVE-2024-33305 | MEDIUM | 6.1 | 0.4% | May 2, 2024 | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter ... |
| CVE-2024-33302 | MEDIUM | 5.3 | 0.3% | May 2, 2024 | SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add ... |
| CVE-2024-23461 | MEDIUM | 5.5 | 0.1% | May 2, 2024 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade pr... |
| CVE-2024-33944 | MEDIUM | 6.5 | 0.5% | May 2, 2024 | Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce... |
| CVE-2024-3005 | MEDIUM | 6.4 | 0.3% | May 2, 2024 | The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2024-33930 | MEDIUM | 4.7 | 0.4% | May 2, 2024 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share Thi... |
| CVE-2024-33922 | MEDIUM | 5.3 | 0.4% | May 2, 2024 | Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Medi... |
| CVE-2024-32638 | MEDIUM | 6.3 | 1.1% | May 2, 2024 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forwa... |
| CVE-2024-3883 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all vers... |
| CVE-2024-3280 | MEDIUM | 6.4 | 0.3% | May 2, 2024 | The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us... |
| CVE-2024-3490 | MEDIUM | 5.4 | 0.3% | May 2, 2024 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-round... |
| CVE-2024-3481 | MEDIUM | 5.2 | 0.3% | May 2, 2024 | The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attacke... |
| CVE-2024-3478 | MEDIUM | 6.1 | 0.2% | May 2, 2024 | The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attack... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now