2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8682MEDIUM5.3The JNews - WordPress Newspaper Magazine Blog AMP Theme theme for WordPress is vulnerable to unauthorized user registrat...
CVE-2024-13866MEDIUM6.4The Simple Notification plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inc...
CVE-2024-13827MEDIUM6.1The Razorpay Subscription Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting d...
CVE-2024-13350MEDIUM5.4The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's...
CVE-2024-0141MEDIUM6.8NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the GPU vBIOS that may allow a malicious actor with tenant level...
CVE-2024-0114HIGH8.1NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious a...
CVE-2024-9135MEDIUM5.3On affected platforms running Arista EOS with BGP Link State configured, BGP peer flap can cause the BGP agent to leak m...
CVE-2024-8000MEDIUM5.3On affected platforms running Arista EOS with 802.1X configured, certain conditions may occur where a dynamic ACL is rec...
CVE-2024-41147CRITICAL9.8An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio ...
CVE-2024-10930HIGH7.8An Uncontrolled Search Path Element vulnerability exists which could allow a malicious actor to perform DLL hijacking an...
CVE-2024-50707CRITICAL10Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to exec...
CVE-2024-50704CRITICAL10Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to exec...
CVE-2024-11957CRITICAL9.3Improper verification of the digital signature in ksojscore.dll in Kingsoft WPS Office in versions equal or less than 12...
CVE-2024-9149HIGH8.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wind Media E-Comme...
CVE-2024-50706CRITICAL9.8Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbi...
CVE-2024-50705HIGH7.1Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote at...
CVE-2024-9618MEDIUM5.4The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ...
CVE-2024-13724MEDIUM4.3The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for Wor...
CVE-2024-13682MEDIUM4.3The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for Wor...
CVE-2024-58050MEDIUM5.5Vulnerability of improper access permission in the HDC module Impact: Successful exploitation of this vulnerability may ...
CVE-2024-58049MEDIUM5.5Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability ...
CVE-2024-58048MEDIUM4.7Multi-thread problem vulnerability in the package management module Impact: Successful exploitation of this vulnerabilit...
CVE-2024-58047MEDIUM5.5Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability ...
CVE-2024-58046MEDIUM5.5Permission management vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may ...
CVE-2024-58045MEDIUM4.7Multi-concurrency vulnerability in the media digital copyright protection module Impact: Successful exploitation of this...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now