2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3753 | MEDIUM | 5.9 | 0.8% | Jul 13, 2024 | The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the pag... |
| CVE-2024-3751 | MEDIUM | 4.8 | 0.5% | Jul 13, 2024 | The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which c... |
| CVE-2024-3710 | MEDIUM | 6.8 | 0.5% | Jul 13, 2024 | The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcod... |
| CVE-2024-3632 | MEDIUM | 6.8 | 0.3% | Jul 13, 2024 | The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, whi... |
| CVE-2024-3026 | MEDIUM | 5.4 | 0.5% | Jul 13, 2024 | The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which... |
| CVE-2024-2870 | MEDIUM | 6.1 | 0.4% | Jul 13, 2024 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting... |
| CVE-2024-31947 | MEDIUM | 6.5 | 0.7% | Jul 12, 2024 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a c... |
| CVE-2024-30213 | HIGH | 8.8 | 1.3% | Jul 12, 2024 | StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injecti... |
| CVE-2024-5902 | MEDIUM | 6.1 | 0.4% | Jul 12, 2024 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera... |
| CVE-2024-40690 | MEDIUM | 5.4 | 0.2% | Jul 12, 2024 | IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb... |
| CVE-2024-40110 | CRITICAL | 9.8 | 1.9% | Jul 12, 2024 | Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability... |
| CVE-2024-40552 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray param... |
| CVE-2024-40551 | HIGH | 8.8 | 0.4% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows at... |
| CVE-2024-40550 | HIGH | 8.8 | 1.0% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.... |
| CVE-2024-40549 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows a... |
| CVE-2024-40548 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attack... |
| CVE-2024-40547 | MEDIUM | 6.5 | 0.3% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component ... |
| CVE-2024-40546 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attacke... |
| CVE-2024-40545 | HIGH | 8.8 | 0.7% | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows att... |
| CVE-2024-40544 | HIGH | 8.8 | 0.5% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#mainten... |
| CVE-2024-40543 | HIGH | 8.8 | 0.3% | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?... |
| CVE-2024-40542 | CRITICAL | 9.8 | 0.4% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
| CVE-2024-40541 | CRITICAL | 9.8 | 0.4% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
| CVE-2024-40540 | CRITICAL | 9.8 | 0.5% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
| CVE-2024-40539 | CRITICAL | 9.8 | 0.5% | Jul 12, 2024 | my-springsecurity-plus before v2024.07.03 was discovered to contain a SQL injection vulnerability via the dataScope para... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now