2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6123 | HIGH | 7.2 | 1.0% | Jul 9, 2024 | The Bit Form plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ic... |
| CVE-2024-5881 | MEDIUM | 6.4 | 0.3% | Jul 9, 2024 | The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc... |
| CVE-2024-37923 | MEDIUM | 5.4 | 0.2% | Jul 9, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.T... |
| CVE-2024-37555 | CRITICAL | 9.8 | 0.6% | Jul 9, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in ZealousWeb Generate PDF using Contact Form 7 generate-p... |
| CVE-2024-28751 | CRITICAL | 9.1 | 0.6% | Jul 9, 2024 | An high privileged remote attacker can enable telnet access that accepts hardcoded credentials. |
| CVE-2024-28750 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a deleting file function to inject OS commands. |
| CVE-2024-28749 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a writing file function to inject OS commands. |
| CVE-2024-28748 | HIGH | 7.2 | 0.8% | Jul 9, 2024 | A remote attacker with high privileges may use a reading file function to inject OS commands. |
| CVE-2024-28747 | CRITICAL | 9.8 | 0.7% | Jul 9, 2024 | An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privilege... |
| CVE-2024-22062 | HIGH | 8.8 | 0.2% | Jul 9, 2024 | There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis... |
| CVE-2024-6334 | MEDIUM | 6.1 | 0.4% | Jul 9, 2024 | The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which cou... |
| CVE-2024-5802 | MEDIUM | 4.8 | 0.4% | Jul 9, 2024 | The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which coul... |
| CVE-2024-5488 | CRITICAL | 9.8 | 3.8% | Jul 9, 2024 | The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with ano... |
| CVE-2024-5441 | HIGH | 8.8 | 1.1% | Jul 9, 2024 | The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat... |
| CVE-2024-3410 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allo... |
| CVE-2024-6171 | MEDIUM | 5.3 | 0.2% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address ... |
| CVE-2024-6170 | MEDIUM | 5.4 | 0.5% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-6169 | MEDIUM | 5.4 | 0.5% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2024-6166 | HIGH | 8.8 | 0.5% | Jul 9, 2024 | The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ... |
| CVE-2024-4667 | MEDIUM | 5.4 | 0.3% | Jul 9, 2024 | The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2024-39600 | MEDIUM | 4.2 | 0.1% | Jul 9, 2024 | Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which... |
| CVE-2024-39599 | MEDIUM | 4.7 | 0.3% | Jul 9, 2024 | Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can by... |
| CVE-2024-39596 | MEDIUM | 4.3 | 0.3% | Jul 9, 2024 | Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which ... |
| CVE-2024-39595 | MEDIUM | 5.4 | 0.2% | Jul 9, 2024 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled input... |
| CVE-2024-39594 | MEDIUM | 6.1 | 0.3% | Jul 9, 2024 | SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled input... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now