2024 CVE Vulnerabilities
39,236 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1534 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode... |
| CVE-2024-2136 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Hea... |
| CVE-2024-1506 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title... |
| CVE-2024-1419 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attrib... |
| CVE-2024-1720 | MEDIUM | 6.1 | 0.5% | Mar 7, 2024 | The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ... |
| CVE-2024-1500 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo ... |
| CVE-2024-1377 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_ta... |
| CVE-2024-1366 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_... |
| CVE-2024-28216 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which ... |
| CVE-2024-1761 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all v... |
| CVE-2024-28097 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting all... |
| CVE-2024-28096 | MEDIUM | 5.4 | 0.4% | Mar 7, 2024 | Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowi... |
| CVE-2024-28095 | MEDIUM | 5.4 | 0.3% | Mar 7, 2024 | News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing... |
| CVE-2024-1460 | MEDIUM | 4.4 | 0.2% | Mar 7, 2024 | MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code... |
| CVE-2024-1443 | MEDIUM | 4.4 | 0.2% | Mar 7, 2024 | MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code ... |
| CVE-2024-24389 | MEDIUM | 6.1 | 0.3% | Mar 7, 2024 | A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts o... |
| CVE-2024-2236 | MEDIUM | 5.9 | 1.1% | Mar 6, 2024 | A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to ... |
| CVE-2024-28111 | MEDIUM | 6.5 | 0.6% | Mar 6, 2024 | Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canaryt... |
| CVE-2024-2215 | MEDIUM | 6.1 | 0.4% | Mar 6, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers ... |
| CVE-2024-28174 | MEDIUM | 5.8 | 0.3% | Mar 6, 2024 | In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized i... |
| CVE-2024-28173 | MEDIUM | 4.3 | 0.5% | Mar 6, 2024 | In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed |
| CVE-2024-28162 | MEDIUM | 4.2 | 0.3% | Mar 6, 2024 | In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable S... |
| CVE-2024-28161 | MEDIUM | 5.3 | 0.4% | Mar 6, 2024 | In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation ... |
| CVE-2024-28159 | MEDIUM | 4.3 | 0.5% | Mar 6, 2024 | A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with ... |
| CVE-2024-28158 | MEDIUM | 4.3 | 0.3% | Mar 6, 2024 | A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now