2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3597MEDIUM6.1The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and inc...
CVE-2024-3562HIGH8.8The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2....
CVE-2024-3561HIGH8.8The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versio...
CVE-2024-3558MEDIUM5.4The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the the 'cfs[post_title]' p...
CVE-2024-1168MEDIUM5.4The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social ima...
CVE-2024-6176MEDIUM4.8Allocation of Resources Without Limits or Throttling vulnerability in LG Electronics LG SuperSign CMS allows Port Scanni...
CVE-2024-6103HIGH8.8Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap co...
CVE-2024-6102HIGH8.8Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially ex...
CVE-2024-6101HIGH8.8Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of ...
CVE-2024-6100HIGH8.8Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a ...
CVE-2024-5182CRITICAL9.1A path traversal vulnerability exists in mudler/localai version 2.14.0, where an attacker can exploit the `model` parame...
CVE-2024-36684CRITICAL9.8In the module "Custom links" (pk_customlinks) <= 2.3 from Promokit.eu for PrestaShop, a guest can perform SQL injection....
CVE-2024-36680HIGH7.5In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The aj...
CVE-2024-36679CRITICAL10In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injectio...
CVE-2024-36678CRITICAL9.8In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can perform SQL inje...
CVE-2024-36677HIGH7.5In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct ...
CVE-2024-34994CRITICAL9.8In the module "Channable" (channable) up to version 3.2.1 from Channable for PrestaShop, a guest can perform SQL injecti...
CVE-2024-34990CRITICAL10In the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for Prest...
CVE-2024-33836CRITICAL9.8In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload fil...
CVE-2024-38358LOW2.9Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink ...
CVE-2024-38357MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte...
CVE-2024-38356MEDIUM6.1TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s conte...
CVE-2024-38355HIGH7.3Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. A specially crafted Socket....
CVE-2024-34993MEDIUM6.3In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy...
CVE-2024-38352Rejected reason: CVE was assigned in error.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now