2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6266 | CRITICAL | 9.8 | 0.5% | Jun 23, 2024 | A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of... |
| CVE-2024-38319 | HIGH | 8.8 | 0.5% | Jun 22, 2024 | IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted s... |
| CVE-2024-5443 | CRITICAL | 9.8 | 1.2% | Jun 22, 2024 | CVE-2024-4320 describes a vulnerability in the parisneo/lollms software, specifically within the `ExtensionBuilder().bui... |
| CVE-2024-6253 | CRITICAL | 9.8 | 0.6% | Jun 22, 2024 | A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this i... |
| CVE-2024-6252 | MEDIUM | 6.1 | 0.4% | Jun 22, 2024 | A vulnerability has been found in Zorlan SkyCaiji up to 2.8 and classified as problematic. Affected by this vulnerabilit... |
| CVE-2024-6251 | MEDIUM | 6.1 | 0.4% | Jun 22, 2024 | A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the... |
| CVE-2024-38379 | MEDIUM | 4.8 | 0.7% | Jun 22, 2024 | Apache Allura's neighborhood settings are vulnerable to a stored XSS attack. Only neighborhood admins can access these ... |
| CVE-2024-5596 | MEDIUM | 6.3 | 0.2% | Jun 22, 2024 | The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ... |
| CVE-2024-4940 | MEDIUM | 6.1 | 1.0% | Jun 22, 2024 | An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows a... |
| CVE-2024-3593 | MEDIUM | 5.4 | 0.2% | Jun 22, 2024 | The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.... |
| CVE-2024-4874 | MEDIUM | 4.3 | 0.3% | Jun 22, 2024 | The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc... |
| CVE-2024-21519 | HIGH | 7.2 | 0.7% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via... |
| CVE-2024-21518 | HIGH | 7.2 | 14.1% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace... |
| CVE-2024-21517 | MEDIUM | 6.1 | 0.4% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirec... |
| CVE-2024-21516 | MEDIUM | 4.7 | 0.4% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identi... |
| CVE-2024-21515 | MEDIUM | 4.7 | 0.4% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filenam... |
| CVE-2024-21514 | HIGH | 8.1 | 19.1% | Jun 22, 2024 | This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido p... |
| CVE-2024-5966 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Grey Opaque theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them... |
| CVE-2024-5965 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's ... |
| CVE-2024-5791 | MEDIUM | 6.1 | 0.3% | Jun 22, 2024 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site ... |
| CVE-2024-5346 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Vid... |
| CVE-2024-4313 | MEDIUM | 5.4 | 0.3% | Jun 22, 2024 | The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter... |
| CVE-2024-2484 | MEDIUM | 5.4 | 0.4% | Jun 22, 2024 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post T... |
| CVE-2024-6120 | MEDIUM | 6.5 | 0.5% | Jun 22, 2024 | The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to ... |
| CVE-2024-37694 | — | — | — | Jun 21, 2024 | Rejected reason: This submission has been rejected by the CNA of record. Authentication is user configurable as describ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now