2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4743HIGH8.8The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to SQL Injection via the orderBy a...
CVE-2024-1272HIGH7.5Inclusion of Sensitive Information in Source Code vulnerability in TNB Mobile Solutions Cockpit Software allows Retrieve...
CVE-2024-5453MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-5439MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all vers...
CVE-2024-5006MEDIUM5.4The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-4939MEDIUM5.4The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div s...
CVE-2024-23669HIGH8.8An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0,...
CVE-2024-5222MEDIUM5.4The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for Wo...
CVE-2024-4088MEDIUM4.3The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2024-2368MEDIUM4.3The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-1164MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form...
CVE-2024-4886MEDIUM4.3The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in t...
CVE-2024-4295CRITICAL9.8The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘hash’ parameter in...
CVE-2024-3667MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of mu...
CVE-2024-2087MEDIUM6.1The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in a...
CVE-2024-1940MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versi...
CVE-2024-1161MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attri...
CVE-2024-5149MEDIUM5.3The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8...
CVE-2024-34055MEDIUM6.5Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation...
CVE-2024-5262CRITICAL9.8Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows re...
CVE-2024-5483MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2024-5317MEDIUM6.1The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions...
CVE-2024-5636CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. Affected by ...
CVE-2024-4084HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing ...
CVE-2024-5635CRITICAL9.8A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now