2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-37409 | MEDIUM | 5.4 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IdeaBox Creations ... |
| CVE-2024-37278 | MEDIUM | 5.4 | 0.2% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pratik Chas... |
| CVE-2024-37275 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NextScripts NextSc... |
| CVE-2024-37271 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Pri... |
| CVE-2024-37267 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in kaptinlin S... |
| CVE-2024-37265 | MEDIUM | 5.4 | 0.2% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibs... |
| CVE-2024-37264 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Groundhogg ... |
| CVE-2024-37263 | MEDIUM | 5.4 | 0.2% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ThemeLooks ... |
| CVE-2024-37262 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in vCita.Com O... |
| CVE-2024-37261 | MEDIUM | 6.1 | 0.6% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister L... |
| CVE-2024-37259 | MEDIUM | 6.1 | 0.6% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Extended The Ul... |
| CVE-2024-37258 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Social Rock... |
| CVE-2024-37257 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Maciej Bis ... |
| CVE-2024-37246 | MEDIUM | 5.4 | 0.2% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jethin Gall... |
| CVE-2024-37245 | MEDIUM | 6.1 | 0.3% | Jul 22, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vsourz Digi... |
| CVE-2024-40430 | — | — | — | Jul 22, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-37391 | HIGH | 7.8 | 0.3% | Jul 22, 2024 | ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{au... |
| CVE-2024-6271 | MEDIUM | 5.4 | 0.2% | Jul 22, 2024 | The Community Events WordPress plugin before 1.5 does not have CSRF check in place when deleting events, which could all... |
| CVE-2024-6244 | HIGH | 8.8 | 2.6% | Jul 22, 2024 | The PZ Frontend Manager WordPress plugin before 1.0.6 does not have CSRF checks in some places, which could allow attack... |
| CVE-2024-6243 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | The HTML Forms WordPress plugin before 1.3.33 does not sanitize and escape the form message inputs, allowing high-privi... |
| CVE-2024-5973 | HIGH | 8.8 | 0.5% | Jul 22, 2024 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.3.24 does not prevent students from creating instructor ... |
| CVE-2024-5529 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | The WP QuickLaTeX WordPress plugin before 3.8.8 does not sanitise and escape some of its settings, which could allow hig... |
| CVE-2024-5004 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign setti... |
| CVE-2024-41709 | MEDIUM | 4.8 | 0.3% | Jul 22, 2024 | Backdrop CMS before 1.27.3 and 1.28.x before 1.28.2 does not sufficiently sanitize field labels before they are displaye... |
| CVE-2024-41704 | CRITICAL | 9.8 | 0.7% | Jul 22, 2024 | LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now