2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37124CRITICAL9.8Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited,...
CVE-2024-36978HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: sched: sch_multiq: fix possible OOB write in m...
CVE-2024-36480CRITICAL9.8Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability...
CVE-2024-36252MEDIUM6.3Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3....
CVE-2024-1407MEDIUM5.4The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2024-6132HIGH8.8The Pexels: Free Stock Photos plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2024-5853HIGH8.8The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2024-5574HIGH7.5The WP Magazine Modules Lite plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inclu...
CVE-2024-5343HIGH8.8The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery ...
CVE-2024-5208MEDIUM6.5An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. T...
CVE-2024-3229CRITICAL9.8The Salon booking system plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-35298MEDIUM4.3Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 all...
CVE-2024-5768MEDIUM6.4The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-5724HIGH8.8The Photo Video Gallery Master plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc...
CVE-2024-5649HIGH8.8The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1....
CVE-2024-5021CRITICAL9.3The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in a...
CVE-2024-4873MEDIUM4.3The Replace Image plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl...
CVE-2024-4787MEDIUM5.8The Cost Calculator Builder PRO for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, ...
CVE-2024-4663MEDIUM6.4The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ param...
CVE-2024-4623MEDIUM6.4The Blogmentor – Blog Layouts for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p...
CVE-2024-4541MEDIUM4.3The Custom Product List Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-4450MEDIUM6.3The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to unauthorized access due to a missing...
CVE-2024-3984MEDIUM6.4The EmbedSocial – Social Media Feeds, Reviews and Galleries plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-2381HIGH8.8The AliExpress Dropshipping with AliNext Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missin...
CVE-2024-6125HIGH8.1The Login with phone number plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now