2024 CVE Vulnerabilities
39,239 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-8016 | HIGH | 7.2 | 0.7% | Aug 30, 2024 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... |
| CVE-2024-42412 | MEDIUM | 6.1 | 0.2% | Aug 30, 2024 | Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in... |
| CVE-2024-39300 | LOW | 3.7 | 0.5% | Aug 30, 2024 | Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function... |
| CVE-2024-34577 | MEDIUM | 6.1 | 0.2% | Aug 30, 2024 | Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to ... |
| CVE-2024-8333 | — | — | — | Aug 30, 2024 | Rejected reason: Test CVE |
| CVE-2024-3673 | CRITICAL | 9.1 | 5.6% | Aug 30, 2024 | The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), whic... |
| CVE-2024-5879 | MEDIUM | 5.4 | 0.4% | Aug 30, 2024 | The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2024-3998 | MEDIUM | 5.4 | 0.2% | Aug 30, 2024 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a... |
| CVE-2024-2694 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d... |
| CVE-2024-5784 | HIGH | 7.1 | 0.4% | Aug 30, 2024 | The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing ... |
| CVE-2024-5061 | MEDIUM | 5.4 | 0.3% | Aug 30, 2024 | The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wr... |
| CVE-2024-5024 | MEDIUM | 6.1 | 0.3% | Aug 30, 2024 | The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr... |
| CVE-2024-4401 | MEDIUM | 5.4 | 0.3% | Aug 30, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_sli... |
| CVE-2024-8330 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula... |
| CVE-2024-8329 | HIGH | 8.8 | 0.6% | Aug 30, 2024 | 6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit... |
| CVE-2024-8328 | MEDIUM | 5.4 | 0.3% | Aug 30, 2024 | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific pa... |
| CVE-2024-8327 | HIGH | 8.8 | 0.7% | Aug 30, 2024 | Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p... |
| CVE-2024-45492 | CRITICAL | 9.8 | 1.4% | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_grou... |
| CVE-2024-45491 | CRITICAL | 9.8 | 1.1% | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on... |
| CVE-2024-45490 | HIGH | 7.5 | 1.7% | Aug 30, 2024 | An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. |
| CVE-2024-45488 | CRITICAL | 9.8 | 50.2% | Aug 30, 2024 | One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to c... |
| CVE-2024-8234 | CRITICAL | 9.8 | 4.4% | Aug 30, 2024 | ** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and ... |
| CVE-2024-2881 | HIGH | 8.8 | 0.5% | Aug 30, 2024 | Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6... |
| CVE-2024-1545 | HIGH | 8.8 | 0.5% | Aug 29, 2024 | Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on... |
| CVE-2024-1543 | MEDIUM | 5.5 | 0.2% | Aug 29, 2024 | The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacke... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now