2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6553 | MEDIUM | 5.3 | 0.4% | Jul 24, 2024 | The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all version... |
| CVE-2024-6836 | MEDIUM | 4.3 | 0.3% | Jul 24, 2024 | The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ... |
| CVE-2024-6094 | MEDIUM | 4.8 | 0.4% | Jul 24, 2024 | The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high pr... |
| CVE-2024-40767 | MEDIUM | 6.5 | 0.9% | Jul 24, 2024 | In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actuall... |
| CVE-2024-5861 | MEDIUM | 6.5 | 0.4% | Jul 24, 2024 | The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a mi... |
| CVE-2024-3246 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2024-7027 | HIGH | 7.3 | 0.4% | Jul 24, 2024 | The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ... |
| CVE-2024-6756 | HIGH | 8.8 | 0.8% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2024-6755 | MEDIUM | 5.3 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing... |
| CVE-2024-6754 | MEDIUM | 4.3 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c... |
| CVE-2024-6753 | MEDIUM | 6.1 | 0.8% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in... |
| CVE-2024-6752 | MEDIUM | 5.4 | 0.2% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in ... |
| CVE-2024-6751 | MEDIUM | 6.5 | 0.2% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including... |
| CVE-2024-6750 | HIGH | 7.5 | 0.3% | Jul 24, 2024 | The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ... |
| CVE-2024-41656 | MEDIUM | 5.4 | 0.4% | Jul 23, 2024 | Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1,... |
| CVE-2024-38176 | HIGH | 8.1 | 0.9% | Jul 23, 2024 | An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate pri... |
| CVE-2024-38164 | HIGH | 8.8 | 0.9% | Jul 23, 2024 | An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne... |
| CVE-2024-0981 | HIGH | 7.1 | 0.3% | Jul 23, 2024 | Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. T... |
| CVE-2024-41668 | HIGH | 8.3 | 0.6% | Jul 23, 2024 | The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data se... |
| CVE-2024-41665 | MEDIUM | 5.4 | 0.4% | Jul 23, 2024 | Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnera... |
| CVE-2024-41661 | — | — | — | Jul 23, 2024 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-50094. Reason: This candidate is a ... |
| CVE-2024-41664 | MEDIUM | 5.4 | 0.4% | Jul 23, 2024 | Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a ... |
| CVE-2024-41178 | HIGH | 7.5 | 0.7% | Jul 23, 2024 | Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e... |
| CVE-2024-6714 | HIGH | 7.8 | 0.3% | Jul 23, 2024 | An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th... |
| CVE-2024-41663 | LOW | 3.5 | 0.3% | Jul 23, 2024 | Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now