2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5858MEDIUM4.3The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-4551HIGH8.8The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi...
CVE-2024-4258CRITICAL9.8The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusi...
CVE-2024-4095MEDIUM6.4The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'ex...
CVE-2024-3105CRITICAL9.9The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execu...
CVE-2024-2695MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2024-1399MEDIUM6.4The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-6000HIGH7.1The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improp...
CVE-2024-5871CRITICAL9.8The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc...
CVE-2024-5868MEDIUM5.3The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and inclu...
CVE-2024-5263MEDIUM5.4The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and T...
CVE-2024-4479MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_en...
CVE-2024-3815MEDIUM4.8The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page i...
CVE-2024-3814MEDIUM4.8The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module i...
CVE-2024-3813HIGH8.8The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8...
CVE-2024-2544MEDIUM6.4The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss...
CVE-2024-6003HIGH7.3A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been clas...
CVE-2024-30120LOW2.9HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.
CVE-2024-30119LOW3.7HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header.  This could allow an attacke...
CVE-2024-21988MEDIUM5.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of se...
CVE-2024-2875Rejected reason: ** REJECT ** Duplicate reservation. Please use CVE-2024-4258 instead.
CVE-2024-37889MEDIUM6.5MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while sign...
CVE-2024-37831CRITICAL9.8Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.
CVE-2024-36600HIGH8.4Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a craft...
CVE-2024-37888MEDIUM6.1The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerabili...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now