2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13568HIGH7.5The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Informati...
CVE-2024-13559MEDIUM6.4The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis...
CVE-2024-13518MEDIUM4.3The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-13358MEDIUM4.3The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to...
CVE-2024-1509CRITICAL9.1Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response h...
CVE-2024-54175MEDIUM5.5IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c...
CVE-2024-44754MEDIUM6.8Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate at...
CVE-2024-10860MEDIUM4.3The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data...
CVE-2024-9195HIGH8.8The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead t...
CVE-2024-9193CRITICAL9.8The WHMpress - WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all vers...
CVE-2024-9019MEDIUM5.4The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-8425CRITICAL9.8The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file...
CVE-2024-8420CRITICAL9.8The DHVC Form plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.4.7. Th...
CVE-2024-13851MEDIUM4.8The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi...
CVE-2024-13832MEDIUM4.3The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an...
CVE-2024-13831HIGH7.2The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including...
CVE-2024-13716MEDIUM4.3The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-13638HIGH7.5The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2024-13469MEDIUM5.4The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link i...
CVE-2024-12820MEDIUM5.4The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' short...
CVE-2024-13796HIGH7.5The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2024-56340MEDIUM6.5IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 is vulnerable to local file inclusion vulnerability, allowing an attacker...
CVE-2024-54173MEDIUM4.7IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD reveals potentially sensitive information in trace files that could be read ...
CVE-2024-12811HIGH8.8The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.9 via s...
CVE-2024-37567CRITICAL9.1Infoblox NIOS through 8.6.4 has Improper Access Control for Grids.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now