2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3112 | MEDIUM | 4.8 | 0.4% | Jul 12, 2024 | The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowin... |
| CVE-2024-2696 | MEDIUM | 4.8 | 0.4% | Jul 12, 2024 | The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c... |
| CVE-2024-2640 | MEDIUM | 5.4 | 0.4% | Jul 12, 2024 | The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users... |
| CVE-2024-2430 | MEDIUM | 5.4 | 0.3% | Jul 12, 2024 | The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcod... |
| CVE-2024-0974 | MEDIUM | 4.8 | 0.3% | Jul 12, 2024 | The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could all... |
| CVE-2024-6677 | HIGH | 7.8 | 0.2% | Jul 12, 2024 | Privilege escalation in uberAgent |
| CVE-2024-1375 | MEDIUM | 4.3 | 0.2% | Jul 12, 2024 | The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on t... |
| CVE-2024-6396 | CRITICAL | 9.8 | 53.4% | Jul 12, 2024 | A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any fi... |
| CVE-2024-6392 | MEDIUM | 5.4 | 0.3% | Jul 11, 2024 | The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modificat... |
| CVE-2024-6468 | HIGH | 7.5 | 0.5% | Jul 11, 2024 | Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP list... |
| CVE-2024-36435 | CRITICAL | 9.8 | 1.3% | Jul 11, 2024 | An issue was discovered on Supermicro BMC firmware in select X11, X12, H12, B12, X13, H13, and B13 motherboards (and CMM... |
| CVE-2024-6531 | — | — | — | Jul 11, 2024 | Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe o... |
| CVE-2024-6681 | CRITICAL | 9.8 | 0.5% | Jul 11, 2024 | A vulnerability, which was classified as critical, has been found in witmy my-springsecurity-plus up to 2024-07-04. Affe... |
| CVE-2024-6485 | MEDIUM | 6.4 | 0.5% | Jul 11, 2024 | A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vuln... |
| CVE-2024-6484 | — | — | — | Jul 11, 2024 | Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe o... |
| CVE-2024-39553 | MEDIUM | 6.9 | 0.4% | Jul 11, 2024 | An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allow... |
| CVE-2024-39552 | HIGH | 8.7 | 0.6% | Jul 11, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Ju... |
| CVE-2024-39551 | HIGH | 8.7 | 0.5% | Jul 11, 2024 | An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Jun... |
| CVE-2024-39550 | HIGH | 7.1 | 0.3% | Jul 11, 2024 | A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on... |
| CVE-2024-39549 | HIGH | 8.7 | 0.5% | Jul 11, 2024 | A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networ... |
| CVE-2024-39548 | HIGH | 7.5 | 0.5% | Jul 11, 2024 | An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an... |
| CVE-2024-39546 | HIGH | 7.3 | 0.2% | Jul 11, 2024 | A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS E... |
| CVE-2024-39545 | HIGH | 8.7 | 0.5% | Jul 11, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks J... |
| CVE-2024-39543 | HIGH | 7.1 | 0.3% | Jul 11, 2024 | A Buffer Copy without Checking Size of Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Juno... |
| CVE-2024-39542 | HIGH | 8.7 | 0.5% | Jul 11, 2024 | An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now