2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-4655 | MEDIUM | 5.4 | 0.4% | Jul 11, 2024 | The Ultimate Blocks WordPress plugin before 3.1.9 does not validate and escape some of its block options before outputt... |
| CVE-2024-1845 | HIGH | 8.8 | 0.3% | Jul 11, 2024 | The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, whic... |
| CVE-2024-22280 | HIGH | 8.1 | 0.5% | Jul 11, 2024 | VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authent... |
| CVE-2024-6554 | MEDIUM | 5.3 | 0.5% | Jul 11, 2024 | The Branda – White Label WordPress, Custom Login Page Customizer plugin for WordPress is vulnerable to Full Path Disclos... |
| CVE-2024-6397 | CRITICAL | 9.8 | 0.7% | Jul 11, 2024 | The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to authentication bypass in all ... |
| CVE-2024-0619 | MEDIUM | 5.3 | 0.4% | Jul 11, 2024 | The Payflex Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2024-6676 | HIGH | 8.8 | 0.4% | Jul 11, 2024 | A vulnerability has been found in witmy my-springsecurity-plus up to 2024-07-03 and classified as critical. Affected by ... |
| CVE-2024-6210 | MEDIUM | 5.3 | 0.6% | Jul 11, 2024 | The Duplicator plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 1.5.9. T... |
| CVE-2024-23485 | MEDIUM | 4.6 | 0.2% | Jul 11, 2024 | Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation (CWE-1304) in the C... |
| CVE-2024-23317 | MEDIUM | 6.3 | 0.2% | Jul 11, 2024 | External Control of File Name or Path (CWE-73) in the Controller 6000 and Controller 7000 allows an attacker with local ... |
| CVE-2024-23194 | LOW | 3.3 | 0.1% | Jul 11, 2024 | Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker... |
| CVE-2024-22387 | MEDIUM | 6.8 | 0.3% | Jul 11, 2024 | External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000 diagnostic web interface al... |
| CVE-2024-40618 | CRITICAL | 9.6 | 0.4% | Jul 11, 2024 | Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when pr... |
| CVE-2024-6653 | CRITICAL | 9.8 | 0.8% | Jul 11, 2024 | A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability af... |
| CVE-2024-6447 | HIGH | 7.2 | 0.5% | Jul 11, 2024 | The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in a... |
| CVE-2024-6652 | HIGH | 8.8 | 0.6% | Jul 10, 2024 | A vulnerability was found in itsourcecode Gym Management System 1.0. It has been classified as critical. This affects an... |
| CVE-2024-6650 | MEDIUM | 4.8 | 0.5% | Jul 10, 2024 | A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problema... |
| CVE-2024-6037 | CRITICAL | 9.1 | 10.6% | Jul 10, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any loc... |
| CVE-2024-6036 | CRITICAL | 9.1 | 10.8% | Jul 10, 2024 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending ... |
| CVE-2024-39565 | HIGH | 8.8 | 0.5% | Jul 10, 2024 | An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juni... |
| CVE-2024-39562 | HIGH | 8.7 | 0.4% | Jul 10, 2024 | A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH da... |
| CVE-2024-39561 | MEDIUM | 6.9 | 0.3% | Jul 10, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the flow daemon (flowd) of Juniper Networks Jun... |
| CVE-2024-39560 | HIGH | 7.1 | 0.2% | Jul 10, 2024 | An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Ju... |
| CVE-2024-39559 | HIGH | 8.2 | 0.4% | Jul 10, 2024 | An Improper Check for Unusual or Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS ... |
| CVE-2024-39558 | HIGH | 7.1 | 0.3% | Jul 10, 2024 | An Unchecked Return Value vulnerability in the Routing Protocol Daemon (rpd) on Juniper Networks Junos OS and Juniper Ne... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now