2024 CVE Vulnerabilities

39,242 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-27776CRITICAL9.8MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow ...
CVE-2024-2178HIGH7.5A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' en...
CVE-2024-5587MEDIUM6.9A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown functi...
CVE-2024-4344MEDIUM4.3The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Cross-Sit...
CVE-2024-35647MEDIUM5.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Global Noti...
CVE-2024-35646MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Erez Hadas-Sonnens...
CVE-2024-35645MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar R...
CVE-2024-4148HIGH7.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10....
CVE-2024-5348HIGH8.8The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includi...
CVE-2024-3821HIGH7.3The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unau...
CVE-2024-3820CRITICAL10The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to SQL ...
CVE-2024-3200MEDIUM6.5The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'slug' attribute of the 'wpforo' shortcode ...
CVE-2024-35636MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uplo...
CVE-2024-4958HIGH7.1The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...
CVE-2024-2295MEDIUM6.4The Contact Form Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [xyz-cfm-for...
CVE-2024-2506MEDIUM6.4The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to St...
CVE-2024-1324MEDIUM5.3The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabili...
CVE-2024-5501MEDIUM6.4The Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-4342MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-4087MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-3565MEDIUM5.4The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-3564HIGH8.8The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2024-4711MEDIUM5.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-2933MEDIUM6.4The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the S...
CVE-2024-5138HIGH8.1The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now