2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-0163 | MEDIUM | 6.3 | 0.1% | Mar 13, 2024 | Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privi... |
| CVE-2024-2293 | MEDIUM | 6.4 | 0.6% | Mar 13, 2024 | The Site Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user display name in all vers... |
| CVE-2024-2286 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Slider... |
| CVE-2024-2252 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable... |
| CVE-2024-2239 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Premium Magic Scroll mo... |
| CVE-2024-2238 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Mouse Cursor mod... |
| CVE-2024-2237 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Global Badge module in ... |
| CVE-2024-2126 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Registration Form w... |
| CVE-2024-2030 | MEDIUM | 6.4 | 0.6% | Mar 13, 2024 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-2028 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Covid-19 St... |
| CVE-2024-2020 | MEDIUM | 6.1 | 0.6% | Mar 13, 2024 | The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href para... |
| CVE-2024-2000 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | The Premium Addons PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'navigation_dots' param... |
| CVE-2024-28683 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via create file. |
| CVE-2024-28682 | MEDIUM | 6.3 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/sys_cache_up.php. |
| CVE-2024-28681 | MEDIUM | 6.1 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/plus_edit.php. |
| CVE-2024-28680 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_add.php. |
| CVE-2024-28679 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via Photo Collection. |
| CVE-2024-28678 | MEDIUM | 6.3 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article... |
| CVE-2024-28677 | MEDIUM | 6.1 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/article_keywords_main... |
| CVE-2024-28676 | MEDIUM | 6.1 | 0.5% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a cross-site scripting (XSS) vulnerability via /dede/article_edit.php. |
| CVE-2024-28672 | MEDIUM | 5.4 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/media_edit.php. |
| CVE-2024-28670 | MEDIUM | 6.1 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_main.php. |
| CVE-2024-28669 | MEDIUM | 5.4 | 0.2% | Mar 13, 2024 | DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/freelist_edit.php. |
| CVE-2024-25101 | MEDIUM | 4.8 | 0.4% | Mar 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yonifre Maspik – S... |
| CVE-2024-25099 | MEDIUM | 5.4 | 0.4% | Mar 13, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David de Boer Payt... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now