2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-36779CRITICAL9.8Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.
CVE-2024-5489MEDIUM4.3The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missin...
CVE-2024-5673MEDIUM6.1Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the ...
CVE-2024-5658MEDIUM6.5The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validi...
CVE-2024-5657HIGH8.1The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the curr...
CVE-2024-5188MEDIUM5.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-5038MEDIUM5.4The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s)...
CVE-2024-5329HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL I...
CVE-2024-5259MEDIUM5.4The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to Stored...
CVE-2024-5221MEDIUM5.4The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all ve...
CVE-2024-5089Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-36394CRITICAL9.8SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-36393CRITICAL9.8SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2024-28995HIGH7.5SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive fil...
CVE-2024-5665MEDIUM4.3The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2024-4177CRITICAL9.8A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to ca...
CVE-2024-3049MEDIUM5.9A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), i...
CVE-2024-5656Rejected reason: ** REJECT ** Accidental duplicate assignment of CVE-2024-4755. Please use CVE-2024-4755.
CVE-2024-5615MEDIUM5.3The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2024-5449MEDIUM4.3The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plu...
CVE-2024-5162MEDIUM5.4The WordPress prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in a...
CVE-2024-5161MEDIUM5.4The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin f...
CVE-2024-5153CRITICAL9.8The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and incl...
CVE-2024-5152MEDIUM5.4The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ p...
CVE-2024-5141MEDIUM5.4The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now