2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6507 | HIGH | 8.1 | 1.1% | Jul 4, 2024 | Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API |
| CVE-2024-5943 | HIGH | 8.8 | 0.3% | Jul 4, 2024 | The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2024-32754 | LOW | 3.1 | 0.2% | Jul 4, 2024 | Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast i... |
| CVE-2024-6434 | MEDIUM | 4.3 | 0.6% | Jul 4, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in a... |
| CVE-2024-6319 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u... |
| CVE-2024-6318 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'u... |
| CVE-2024-3904 | HIGH | 8.8 | 0.2% | Jul 4, 2024 | Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-V... |
| CVE-2024-39884 | MEDIUM | 6.2 | 0.9% | Jul 4, 2024 | A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of... |
| CVE-2024-1574 | MEDIUM | 6.7 | 0.2% | Jul 4, 2024 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in the licensing featur... |
| CVE-2024-1573 | MEDIUM | 5.9 | 0.6% | Jul 4, 2024 | Missing Authentication for Critical Function vulnerability in the mobile monitoring feature of Mitsubishi Electric GENES... |
| CVE-2024-1182 | HIGH | 7 | 0.3% | Jul 4, 2024 | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi E... |
| CVE-2024-5641 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | The One Click Order Re-Order plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2024-3639 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pos... |
| CVE-2024-3638 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Marq... |
| CVE-2024-2926 | MEDIUM | 5.4 | 0.4% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widg... |
| CVE-2024-2385 | HIGH | 8.8 | 0.9% | Jul 4, 2024 | The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2024-38471 | MEDIUM | 6.8 | 0.4% | Jul 4, 2024 | Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS com... |
| CVE-2024-38345 | HIGH | 8.1 | 0.3% | Jul 4, 2024 | A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is... |
| CVE-2024-38344 | MEDIUM | 5.4 | 0.3% | Jul 4, 2024 | A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is ex... |
| CVE-2024-6284 | HIGH | 7.3 | 0.3% | Jul 3, 2024 | In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables conf... |
| CVE-2024-6383 | MEDIUM | 5.3 | 0.6% | Jul 3, 2024 | The bson_string_append function in MongoDB C Driver may be vulnerable to a buffer overflow where the function might atte... |
| CVE-2024-6464 | — | — | — | Jul 3, 2024 | Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-53... |
| CVE-2024-6463 | — | — | — | Jul 3, 2024 | Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-53... |
| CVE-2024-6461 | — | — | — | Jul 3, 2024 | Rejected reason: **REJECT** This is a duplicate CVE issued in error on a framework vulnerability. Please use CVE-2024-53... |
| CVE-2024-39683 | MEDIUM | 6.5 | 0.6% | Jul 3, 2024 | ZITADEL is an open-source identity infrastructure tool. ZITADEL provides users the ability to list all user sessions of ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now