2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25142MEDIUM5.5Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cac...
CVE-2024-5995HIGH8.8The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the sessi...
CVE-2024-5961MEDIUM5.3Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cros...
CVE-2024-5577CRITICAL9.8The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the...
CVE-2024-5465MEDIUM5.5Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availa...
CVE-2024-5464LOW3.3Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vul...
CVE-2024-36503MEDIUM5.5Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect ...
CVE-2024-36502MEDIUM5.5Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect a...
CVE-2024-36501MEDIUM5.5Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect ...
CVE-2024-36500MEDIUM5.5Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect se...
CVE-2024-36499MEDIUM5.5Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerabili...
CVE-2024-5994MEDIUM5.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS...
CVE-2024-31163HIGH7.2ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privile...
CVE-2024-31162HIGH7.2The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote a...
CVE-2024-5551HIGH8.8The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2024-5155MEDIUM6.1The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as ...
CVE-2024-4751MEDIUM4.3The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which coul...
CVE-2024-4480MEDIUM6.1The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, whic...
CVE-2024-4404CRITICAL9.6The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, ...
CVE-2024-4271MEDIUM4.6The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the a...
CVE-2024-4270MEDIUM5.4The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the aut...
CVE-2024-4005MEDIUM4.8The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-3993MEDIUM4.6The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as wel...
CVE-2024-3992MEDIUM4.8The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-3978MEDIUM5.4The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now