2024 CVE Vulnerabilities
39,235 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-29112 | MEDIUM | 4.8 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marketing Robot... |
| CVE-2024-29111 | MEDIUM | 6.5 | 0.3% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Sitekit ... |
| CVE-2024-29109 | MEDIUM | 5.4 | 0.3% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jan-Peter Lambeck ... |
| CVE-2024-1401 | MEDIUM | 4.8 | 0.4% | Mar 19, 2024 | The Profile Box Shortcode And Widget WordPress plugin before 1.2.1 does not sanitise and escape some of its settings, wh... |
| CVE-2024-29141 | MEDIUM | 5.5 | 0.3% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PDF Embedder allow... |
| CVE-2024-29140 | MEDIUM | 5.9 | 0.3% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt Manning MJM C... |
| CVE-2024-29138 | MEDIUM | 6.1 | 0.6% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Joachim Jensen Res... |
| CVE-2024-29137 | MEDIUM | 6.1 | 0.6% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic t... |
| CVE-2024-29134 | MEDIUM | 5.4 | 0.3% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themefic Tourfic t... |
| CVE-2024-29130 | MEDIUM | 6.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Con... |
| CVE-2024-29129 | MEDIUM | 6.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPLIT Pty Ltd OxyE... |
| CVE-2024-29128 | MEDIUM | 6.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Post SMTP POST SMT... |
| CVE-2024-29127 | MEDIUM | 6.1 | 0.4% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AAM Advanced Acces... |
| CVE-2024-28734 | MEDIUM | 6.1 | 1.8% | Mar 19, 2024 | Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary... |
| CVE-2024-29143 | MEDIUM | 6.5 | 0.3% | Mar 19, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs, sareio... |
| CVE-2024-2634 | MEDIUM | 6.1 | 0.3% | Mar 19, 2024 | A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint ... |
| CVE-2024-2633 | MEDIUM | 6.1 | 0.3% | Mar 19, 2024 | A Cross-Site Scripting Vulnerability has been found on Meta4 HR affecting version 819.001.022 and earlier. The endpoint ... |
| CVE-2024-2611 | MEDIUM | 5.5 | 0.6% | Mar 19, 2024 | A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissi... |
| CVE-2024-2610 | MEDIUM | 6.1 | 0.7% | Mar 19, 2024 | Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content ... |
| CVE-2024-2609 | MEDIUM | 6.1 | 0.6% | Mar 19, 2024 | The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjackin... |
| CVE-2024-2605 | MEDIUM | 5.9 | 0.6% | Mar 19, 2024 | An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *N... |
| CVE-2024-1146 | MEDIUM | 6.1 | 0.3% | Mar 19, 2024 | Cross-Site Scripting vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability c... |
| CVE-2024-1145 | MEDIUM | 5.3 | 0.5% | Mar 19, 2024 | User enumeration vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerability could... |
| CVE-2024-1144 | MEDIUM | 6.5 | 0.3% | Mar 19, 2024 | Improper access control vulnerability in Devklan's Alma Blog that affects versions 2.1.10 and earlier. This vulnerabilit... |
| CVE-2024-27439 | MEDIUM | 6.5 | 0.7% | Mar 19, 2024 | An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. T... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now