2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-40898 | HIGH | 7.5 | 1.5% | Jul 18, 2024 | SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes t... |
| CVE-2024-40725 | MEDIUM | 5.3 | 4.1% | Jul 18, 2024 | A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type b... |
| CVE-2024-5555 | MEDIUM | 6.4 | 0.5% | Jul 18, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-5554 | MEDIUM | 6.4 | 0.3% | Jul 18, 2024 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W... |
| CVE-2024-3242 | HIGH | 8.8 | 1.0% | Jul 18, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension vali... |
| CVE-2024-40764 | HIGH | 7.5 | 0.7% | Jul 18, 2024 | Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Den... |
| CVE-2024-29014 | HIGH | 8.8 | 1.8% | Jul 18, 2024 | Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an att... |
| CVE-2024-41011 | HIGH | 7.8 | 0.2% | Jul 18, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page w... |
| CVE-2024-6164 | CRITICAL | 9.8 | 1.1% | Jul 18, 2024 | The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. T... |
| CVE-2024-6705 | MEDIUM | 5.5 | 0.3% | Jul 18, 2024 | The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,... |
| CVE-2024-6599 | MEDIUM | 4.3 | 0.3% | Jul 18, 2024 | The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capabil... |
| CVE-2024-6175 | MEDIUM | 5.4 | 0.3% | Jul 18, 2024 | The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modificati... |
| CVE-2024-5964 | MEDIUM | 6.4 | 0.3% | Jul 18, 2024 | The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme... |
| CVE-2024-5726 | HIGH | 8.8 | 0.7% | Jul 18, 2024 | The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi... |
| CVE-2024-41184 | CRITICAL | 9.8 | 0.6% | Jul 18, 2024 | In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: ... |
| CVE-2024-39682 | MEDIUM | 5.4 | 0.4% | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up ... |
| CVE-2024-39681 | HIGH | 8.8 | 0.3% | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS... |
| CVE-2024-39680 | HIGH | 8.8 | 0.3% | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS... |
| CVE-2024-39679 | HIGH | 8.8 | 0.3% | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS... |
| CVE-2024-39678 | HIGH | 8.8 | 0.3% | Jul 18, 2024 | Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in version... |
| CVE-2024-40492 | HIGH | 7.1 | 0.8% | Jul 17, 2024 | Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the... |
| CVE-2024-40402 | MEDIUM | 6.3 | 0.4% | Jul 17, 2024 | A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulne... |
| CVE-2024-40119 | HIGH | 8.8 | 0.5% | Jul 17, 2024 | Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (... |
| CVE-2024-39126 | MEDIUM | 5.4 | 0.3% | Jul 17, 2024 | Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents. |
| CVE-2024-39125 | MEDIUM | 5.4 | 0.3% | Jul 17, 2024 | Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header. |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now