2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-43051MEDIUM5.5Information disclosure while deriving keys for a session for any Widevine use case.
CVE-2024-38426MEDIUM5.3While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-24778MEDIUM6.5Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resou...
CVE-2024-10925MEDIUM5.3A vulnerability in GitLab-EE affecting all versions from 16.2 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 1...
CVE-2024-8186MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 16.6 before 17.7.6, 17.8 before 17.8.4, and 17....
CVE-2024-53386MEDIUM6.1Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di...
CVE-2024-53382MEDIUM5.4Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ...
CVE-2024-36353MEDIUM6.5Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem...
CVE-2024-55907MEDIUM5.3IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno...
CVE-2024-41778MEDIUM6.5IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi...
CVE-2024-13833HIGH7.2The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, ...
CVE-2024-13546MEDIUM4.3The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2024-13910HIGH7.2The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file ...
CVE-2024-13697MEDIUM6.5The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2024-13611HIGH7.5The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2024-13911HIGH7.2The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Sensitive Infor...
CVE-2024-13806MEDIUM6.5The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl...
CVE-2024-12544HIGH8.8The SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity plugin for ...
CVE-2024-13373HIGH8.1The Exertio Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up...
CVE-2024-12824CRITICAL9.8The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in ...
CVE-2024-13901MEDIUM4.8The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to...
CVE-2024-9217MEDIUM6.1The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us...
CVE-2024-9212MEDIUM6.1The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
CVE-2024-13750MEDIUM6.5The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or...
CVE-2024-13746MEDIUM6.5The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now