2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5484Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-22338MEDIUM5.5IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to...
CVE-2024-5347MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribu...
CVE-2024-5041MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-...
CVE-2024-4160MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packag...
CVE-2024-23692CRITICAL9.8Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vu...
CVE-2024-5436CRITICAL9.8Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. ...
CVE-2024-5525HIGH8.8Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a loca...
CVE-2024-5524MEDIUM5.3Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered us...
CVE-2024-5523HIGH8.8SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated ...
CVE-2024-5427MEDIUM5.4The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is v...
CVE-2024-4469HIGH7.5The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role...
CVE-2024-4379MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Glob...
CVE-2024-4376MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fanc...
CVE-2024-4205MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa...
CVE-2024-36246CRITICAL9.8Missing authorization vulnerability exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co...
CVE-2024-23847MEDIUM5.9Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co...
CVE-2024-2793HIGH7.2The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-37032HIGH8.8Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path,...
CVE-2024-5418MEDIUM5.4The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'slitems' attribu...
CVE-2024-5345HIGH8.8The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up ...
CVE-2024-32850CRITICAL9.8Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 ...
CVE-2024-37018CRITICAL9.1The OpenDaylight 0.15.3 controller allows topology poisoning via API requests because an application can manipulate the ...
CVE-2024-37017HIGH8.1asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_Time...
CVE-2024-5499HIGH8.8Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitra...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now