2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4661MEDIUM4.3The WP Reset plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-5770MEDIUM4.3The WP Force SSL & HTTPS SSL Redirect plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2024-3668HIGH8.8The PowerPack Pro for Elementor plugin for WordPress is vulnerable to privilege escalation in all versions up to, and in...
CVE-2024-5663MEDIUM5.4The Cards for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Cards wi...
CVE-2024-0444HIGH8.8GStreamer AV1 Video Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2024-1694HIGH7.8Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass d...
CVE-2024-5761Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: [CVE-2024-5260]. Reason: This candidate is a...
CVE-2024-3133Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-37388CRITICAL9.1An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers...
CVE-2024-36827HIGH7.5An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows atta...
CVE-2024-36811Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-37295. Reason: This candidate is a reservation d...
CVE-2024-23595Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-5745CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been classified as critical. Affecte...
CVE-2024-4152Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-3380Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-37163HIGH7.5SkyScrape is a GUI Dashboard for AWS Infrastructure and Managing Resources and Usage Costs. SkyScrape's API requests ar...
CVE-2024-32502HIGH8.4An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ...
CVE-2024-31959HIGH7.8An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the vali...
CVE-2024-31958HIGH7.8An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the val...
CVE-2024-30163CRITICAL9.8Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\...
CVE-2024-30162HIGH7.2Invision Community through 4.7.16 allows remote code execution via the applications/core/modules/admin/editor/toolbar.ph...
CVE-2024-32503HIGH7.8An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos ...
CVE-2024-37162MEDIUM5.3zsa is a library for building typesafe server actions in Next.js. All users are impacted. The zsa application transfers ...
CVE-2024-36792HIGH8.2An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain acce...
CVE-2024-36790HIGH8.8Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now