2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3977MEDIUM4.8The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which coul...
CVE-2024-3972MEDIUM4.3The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2024-3971MEDIUM4.3The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could a...
CVE-2024-3966MEDIUM6.1The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated...
CVE-2024-3965MEDIUM5.4The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could...
CVE-2024-3754MEDIUM4.7The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could all...
CVE-2024-2218MEDIUM4.6The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which co...
CVE-2024-2122MEDIUM5.4The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via alb...
CVE-2024-23504MEDIUM5.3Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through ...
CVE-2024-1295MEDIUM6.5The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not pr...
CVE-2024-4936CRITICAL9.8The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via th...
CVE-2024-3498HIGH7.8Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page an...
CVE-2024-3497HIGH8.8Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add...
CVE-2024-3496HIGH8.8Attackers can bypass the web login authentication process to gain access to the printer's system information and upload ...
CVE-2024-1094HIGH7.3The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress...
CVE-2024-5469MEDIUM4.3DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an a...
CVE-2024-31161HIGH7.2The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrati...
CVE-2024-31160MEDIUM4.8The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke...
CVE-2024-31159MEDIUM4.8The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke...
CVE-2024-27180MEDIUM6.7An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the refe...
CVE-2024-27179MEDIUM4.7Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. ...
CVE-2024-27178HIGH7.2An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name var...
CVE-2024-27177HIGH7.2An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name ...
CVE-2024-27176HIGH7.2An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID var...
CVE-2024-27175MEDIUM4.4Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can r...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now