2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-38676 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Booking Ult... |
| CVE-2024-38675 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LOOS,Inc. A... |
| CVE-2024-38674 | MEDIUM | 5.4 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SKT Themes ... |
| CVE-2024-38673 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Info... |
| CVE-2024-38672 | HIGH | 7.1 | 0.4% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in namithjawah... |
| CVE-2024-38671 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibs... |
| CVE-2024-38670 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Member... |
| CVE-2024-38669 | HIGH | 7.1 | 0.4% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in a3rev Softw... |
| CVE-2024-37961 | HIGH | 7.1 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in codoc.Jp al... |
| CVE-2024-37960 | MEDIUM | 6.5 | 0.3% | Jul 20, 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chris Coyie... |
| CVE-2024-6491 | MEDIUM | 4.3 | 0.4% | Jul 20, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-6489 | MEDIUM | 5.3 | 0.3% | Jul 20, 2024 | The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2024-6694 | LOW | 2.7 | 0.6% | Jul 20, 2024 | The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1.... |
| CVE-2024-6281 | HIGH | 7.3 | 0.3% | Jul 20, 2024 | A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `... |
| CVE-2024-40348 | HIGH | 8.2 | 8.3% | Jul 20, 2024 | An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory... |
| CVE-2024-40347 | MEDIUM | 6.1 | 0.4% | Jul 20, 2024 | A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute ... |
| CVE-2024-3934 | MEDIUM | 6.5 | 0.7% | Jul 20, 2024 | The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.... |
| CVE-2024-6560 | MEDIUM | 5.3 | 0.6% | Jul 20, 2024 | The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up ... |
| CVE-2024-2337 | MEDIUM | 5.4 | 0.3% | Jul 20, 2024 | The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_g... |
| CVE-2024-5804 | MEDIUM | 4.3 | 0.2% | Jul 20, 2024 | The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u... |
| CVE-2024-41599 | MEDIUM | 6.1 | 0.5% | Jul 19, 2024 | Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via th... |
| CVE-2024-41597 | MEDIUM | 4.2 | 0.3% | Jul 19, 2024 | Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: th... |
| CVE-2024-41124 | MEDIUM | 6.3 | 0.3% | Jul 19, 2024 | Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTP... |
| CVE-2024-41122 | HIGH | 8.8 | 0.6% | Jul 19, 2024 | Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t... |
| CVE-2024-41121 | HIGH | 8.8 | 0.7% | Jul 19, 2024 | Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can t... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now