2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5036MEDIUM5.4The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem...
CVE-2024-28147HIGH7.4An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may ...
CVE-2024-34693MEDIUM5.3Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB con...
CVE-2024-29013MEDIUM6.5Heap-based buffer overflow vulnerability in the SonicOS SSL-VPN allows an authenticated remote attacker to cause Denial ...
CVE-2024-29012HIGH7.5Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause De...
CVE-2024-38620MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Remove HCI_AMP support Since BT_HS...
CVE-2024-4098CRITICAL9.8The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 ...
CVE-2024-38619MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb-storage: alauda: Check whether the media is ini...
CVE-2024-6113CRITICAL9.8A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critic...
CVE-2024-5522MEDIUM6.5The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before...
CVE-2024-5475MEDIUM5.4The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes b...
CVE-2024-4565MEDIUM6.5The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 all...
CVE-2024-5686MEDIUM5.4The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-5605HIGH8.8The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter wit...
CVE-2024-4390MEDIUM6.5The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versi...
CVE-2024-5213MEDIUM6.5In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a u...
CVE-2024-6179MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics Sup...
CVE-2024-6178MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LG Electronics Sup...
CVE-2024-6177MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in LG Electron...
CVE-2024-5432CRITICAL9.8The Lifeline Donation plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2....
CVE-2024-4742MEDIUM6.5The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-4626MEDIUM5.4The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘layout_type’ and...
CVE-2024-3627MEDIUM5.4The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2024-3605CRITICAL9.8The WP Hotel Booking plugin for WordPress is vulnerable to SQL Injection via the 'room_type' parameter of the /wphb/v1/r...
CVE-2024-3602MEDIUM4.3The Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer plugin for WordPre...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now