2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-20876HIGH7.8Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to mem...
CVE-2024-20875MEDIUM5.5Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to ac...
CVE-2024-20874HIGH7.8Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch...
CVE-2024-20873MEDIUM6Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attack...
CVE-2024-4997MEDIUM5.3The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links...
CVE-2024-4857MEDIUM6.1The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape some form submissions, which could al...
CVE-2024-4856HIGH8.2The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back...
CVE-2024-4750MEDIUM5.3The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private...
CVE-2024-4749HIGH8.3The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it ...
CVE-2024-4697MEDIUM5.4The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘heading_tag’...
CVE-2024-4462MEDIUM4.4The Nafeza Prayer Time plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi...
CVE-2024-4274MEDIUM4.3The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation...
CVE-2024-4273MEDIUM5.4The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_proper...
CVE-2024-4180CRITICAL9.1The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted content when rendering som...
CVE-2024-4057MEDIUM6.1The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its bloc...
CVE-2024-3555HIGH7.2The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to un...
CVE-2024-3230MEDIUM6.4The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-at...
CVE-2024-3031MEDIUM4.4The Fluid Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2024-2470MEDIUM5.4The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could al...
CVE-2024-2382MEDIUM5.3The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions u...
CVE-2024-2019HIGH7.5The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss...
CVE-2024-1718MEDIUM5.3The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ...
CVE-2024-1717MEDIUM4.3The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2024-0757MEDIUM5.4The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file e...
CVE-2024-3888MEDIUM6.4The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now