2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-31898 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 could allow an authenticated user to read or modify sensitive information by bypa... |
| CVE-2024-28797 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable stored to cross-site scripting. This vulnerability allows users to ... |
| CVE-2024-35119 | MEDIUM | 5.3 | 0.4% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2024-31902 | HIGH | 8.8 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec... |
| CVE-2024-28798 | MEDIUM | 6.1 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to ... |
| CVE-2024-5062 | MEDIUM | 6.1 | 0.4% | Jun 30, 2024 | A reflected Cross-Site Scripting (XSS) vulnerability was identified in zenml-io/zenml version 0.57.1. The vulnerability ... |
| CVE-2024-28795 | MEDIUM | 5.4 | 0.3% | Jun 30, 2024 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2024-6415 | MEDIUM | 5.1 | 0.3% | Jun 30, 2024 | A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is a... |
| CVE-2024-6414 | MEDIUM | 6.9 | 0.6% | Jun 30, 2024 | A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown fun... |
| CVE-2024-5926 | CRITICAL | 9.1 | 0.9% | Jun 30, 2024 | A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbit... |
| CVE-2024-39848 | CRITICAL | 9.1 | 0.4% | Jun 29, 2024 | Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is rela... |
| CVE-2024-39846 | LOW | 3.5 | 0.2% | Jun 29, 2024 | NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthoriz... |
| CVE-2024-39840 | HIGH | 8.8 | 0.6% | Jun 29, 2024 | Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the... |
| CVE-2024-2386 | HIGH | 8.8 | 0.5% | Jun 29, 2024 | The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' paramete... |
| CVE-2024-25943 | CRITICAL | 9.8 | 0.7% | Jun 29, 2024 | iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a sessi... |
| CVE-2024-5819 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to DOM-based Store... |
| CVE-2024-6363 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Stock Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's stock_ticker shortco... |
| CVE-2024-5790 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ attribute... |
| CVE-2024-5666 | MEDIUM | 5.4 | 0.4% | Jun 29, 2024 | The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter w... |
| CVE-2024-6265 | CRITICAL | 9.8 | 2.4% | Jun 29, 2024 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for ... |
| CVE-2024-5942 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Page and Post Clone plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an... |
| CVE-2024-5889 | MEDIUM | 6.1 | 0.3% | Jun 29, 2024 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2024-5598 | HIGH | 7.5 | 0.6% | Jun 29, 2024 | The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an... |
| CVE-2024-5192 | MEDIUM | 5.4 | 0.3% | Jun 29, 2024 | The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ... |
| CVE-2024-6405 | MEDIUM | 5.4 | 0.2% | Jun 29, 2024 | The Floating Social Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now