2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7390 | MEDIUM | 5.3 | 0.3% | Aug 21, 2024 | The WP Testimonial Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2024-7134 | HIGH | 7.2 | 0.4% | Aug 21, 2024 | The LiquidPoll – Polls, Surveys, NPS and Feedback Reviews plugin for WordPress is vulnerable to Stored Cross-Site Script... |
| CVE-2024-7090 | MEDIUM | 6.1 | 0.4% | Aug 21, 2024 | The LH Add Media From Url plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘lh_add_media_fro... |
| CVE-2024-7032 | MEDIUM | 6.5 | 0.5% | Aug 21, 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capab... |
| CVE-2024-7030 | MEDIUM | 4.3 | 0.4% | Aug 21, 2024 | The Smart Online Order for Clover plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2024-7013 | HIGH | 7.8 | 0.3% | Aug 21, 2024 | Stack-based buffer overflow in Control FPWIN Pro version 7.7.2.0 and all previous versions may allow attackers to execut... |
| CVE-2024-6883 | MEDIUM | 4.3 | 0.3% | Aug 21, 2024 | The Event Espresso 4 Decaf – Event Registration Event Ticketing plugin for WordPress is vulnerable to limited unauthoriz... |
| CVE-2024-6767 | MEDIUM | 5.5 | 0.4% | Aug 21, 2024 | The WordSurvey plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sounding_title’ parameter in a... |
| CVE-2024-6568 | MEDIUM | 5.3 | 0.5% | Aug 21, 2024 | The Flamix: Bitrix24 and Contact Form 7 integrations plugin for WordPress is vulnerable to Full Path Disclosure in all v... |
| CVE-2024-6508 | HIGH | 8 | 0.6% | Aug 21, 2024 | An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit gr... |
| CVE-2024-5880 | MEDIUM | 4.3 | 0.3% | Aug 21, 2024 | The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi... |
| CVE-2024-42939 | MEDIUM | 5.4 | 0.3% | Aug 21, 2024 | A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execu... |
| CVE-2024-38305 | HIGH | 7.3 | 0.3% | Aug 21, 2024 | Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the install... |
| CVE-2024-43882 | HIGH | 7 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid... |
| CVE-2024-43881 | HIGH | 7.1 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping re... |
| CVE-2024-43880 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_erp: Fix object nesting warning... |
| CVE-2024-43879 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: handle 2x996 RU allocation in cfg80... |
| CVE-2024-43878 | HIGH | 7.1 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When ther... |
| CVE-2024-43877 | HIGH | 7.1 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In ... |
| CVE-2024-43876 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: PCI: rcar: Demote WARN() to dev_warn_ratelimited() ... |
| CVE-2024-43875 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Clean up error handling in vpci_scan... |
| CVE-2024-43874 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Fix null pointer dereference in __sev... |
| CVE-2024-43873 | HIGH | 7.8 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow The... |
| CVE-2024-43872 | MEDIUM | 5.5 | 0.1% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix soft lockup under heavy CEQE load CE... |
| CVE-2024-43871 | MEDIUM | 5.5 | 0.2% | Aug 21, 2024 | In the Linux kernel, the following vulnerability has been resolved: devres: Fix memory leakage caused by driver API dev... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now