2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8420CRITICAL9.8The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th...
CVE-2024-13851MEDIUM4.8The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi...
CVE-2024-13832MEDIUM4.3The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an...
CVE-2024-13831HIGH7.2The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including...
CVE-2024-13716MEDIUM4.3The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-13638HIGH7.5The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2024-13469MEDIUM5.4The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link i...
CVE-2024-12820MEDIUM5.4The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' short...
CVE-2024-13796HIGH7.5The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2024-56340MEDIUM6.5IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker...
CVE-2024-54173MEDIUM4.7IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read ...
CVE-2024-12811HIGH8.8The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via s...
CVE-2024-37567CRITICAL9.1Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.
CVE-2024-37566CRITICAL9.8Infoblox NIOS through 8.6.4 has Improper Authentication for Grids.
CVE-2024-36047CRITICAL9.8Infoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.
CVE-2024-36046CRITICAL9.8Infoblox NIOS through 8.6.4 executes with more privileges than required.
CVE-2024-38292CRITICAL9.8In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which ma...
CVE-2024-38291HIGH8.8In XIQ-SE before 24.2.11, a low-privileged user may be able to access admin passwords, which could lead to privilege esc...
CVE-2024-38290MEDIUM5.3In XIQ-SE before 24.2.11, a server misconfiguration may allow user enumeration when specific conditions are met.
CVE-2024-55160CRITICAL9.8GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/op...
CVE-2024-51139CRITICAL9.8Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862...
CVE-2024-51138CRITICAL9.8Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3...
CVE-2024-41340HIGH8.4An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior t...
CVE-2024-41339HIGH8.8An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620...
CVE-2024-41338HIGH7.5A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now