2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6579 | MEDIUM | 4.3 | 0.4% | Jul 16, 2024 | The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings m... |
| CVE-2024-39887 | CRITICAL | 9.8 | 4.4% | Jul 16, 2024 | An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL ... |
| CVE-2024-6570 | MEDIUM | 5.3 | 0.5% | Jul 16, 2024 | The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. Th... |
| CVE-2024-6565 | MEDIUM | 5.3 | 0.4% | Jul 16, 2024 | The AForms — Form Builder for Price Calculator & Cost Estimation plugin for WordPress is vulnerable to Full Path Disclos... |
| CVE-2024-5852 | MEDIUM | 4.3 | 0.7% | Jul 16, 2024 | The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including... |
| CVE-2024-3779 | MEDIUM | 5.5 | 0.2% | Jul 16, 2024 | Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker t... |
| CVE-2024-3587 | MEDIUM | 5.4 | 0.4% | Jul 16, 2024 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2024-2691 | MEDIUM | 5.4 | 0.3% | Jul 16, 2024 | The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable ... |
| CVE-2024-1937 | MEDIUM | 6.5 | 0.4% | Jul 16, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2024-41008 | MEDIUM | 5.5 | 0.2% | Jul 16, 2024 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This pat... |
| CVE-2024-6559 | MEDIUM | 5.3 | 0.4% | Jul 16, 2024 | The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path ... |
| CVE-2024-4780 | MEDIUM | 6.4 | 0.5% | Jul 16, 2024 | The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eih... |
| CVE-2024-6557 | MEDIUM | 5.3 | 0.4% | Jul 16, 2024 | The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Pos... |
| CVE-2024-6780 | LOW | 3.3 | 0.2% | Jul 16, 2024 | Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security... |
| CVE-2024-40524 | CRITICAL | 9.8 | 1.4% | Jul 15, 2024 | Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the web... |
| CVE-2024-4143 | CRITICAL | 9.8 | 0.6% | Jul 15, 2024 | A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbit... |
| CVE-2024-40632 | LOW | 3.7 | 0.4% | Jul 15, 2024 | Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the applica... |
| CVE-2024-4224 | MEDIUM | 5.4 | 0.3% | Jul 15, 2024 | An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V... |
| CVE-2024-40630 | MEDIUM | 4.3 | 0.4% | Jul 15, 2024 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2024-40627 | MEDIUM | 5.8 | 0.6% | Jul 15, 2024 | Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by ... |
| CVE-2024-40624 | CRITICAL | 9.8 | 1.0% | Jul 15, 2024 | TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes... |
| CVE-2024-39919 | LOW | 3.1 | 0.4% | Jul 15, 2024 | @jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an... |
| CVE-2024-39918 | MEDIUM | 4.3 | 0.5% | Jul 15, 2024 | @jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an... |
| CVE-2024-39915 | CRITICAL | 9.9 | 0.6% | Jul 15, 2024 | Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This au... |
| CVE-2024-39912 | MEDIUM | 5.3 | 0.4% | Jul 15, 2024 | web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now