2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36789HIGH8.1An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to de...
CVE-2024-36788MEDIUM4.8Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers...
CVE-2024-36787HIGH8.8An issue in Netgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 allows attackers to bypass authentication and access the admin...
CVE-2024-36773MEDIUM4.8A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT...
CVE-2024-37160MEDIUM4.8Formwork is a flat file-based Content Management System (CMS). An attackers (requires administrator privilege) to execut...
CVE-2024-31878MEDIUM5.3IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. Thi...
CVE-2024-5599HIGH7.5The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Sensitive Information Expos...
CVE-2024-5542MEDIUM6.1The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-5438MEDIUM4.3The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Refere...
CVE-2024-5382MEDIUM5.3The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-36673CRITICAL9.8Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerabi...
CVE-2024-5734HIGH8.8A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. Affected is an unknow...
CVE-2024-5733CRITICAL9.8A vulnerability was found in itsourcecode Online Discussion Forum 1.0. It has been rated as critical. This issue affects...
CVE-2024-4610HIGH7.8Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-...
CVE-2024-5637HIGH8.1The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on...
CVE-2024-5732CRITICAL9.8A vulnerability was found in Clash up to 0.20.1 on Windows. It has been declared as critical. This vulnerability affects...
CVE-2024-5645MEDIUM5.4The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_css_id’ parameter withi...
CVE-2024-5481HIGH8.8The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all v...
CVE-2024-5426MEDIUM5.4The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-4703MEDIUM5.4The One Page Express Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's one_pa...
CVE-2024-4489MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cust...
CVE-2024-4488MEDIUM5.4The Royal Elementor Addons and Templates for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘inline_list...
CVE-2024-4451MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_vide...
CVE-2024-5003MEDIUM5.4The WP Stacker WordPress plugin through 1.8.5 does not have CSRF check in some places, and is missing sanitisation as we...
CVE-2024-4756MEDIUM5.4The WP Backpack WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now