2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4043MEDIUM6.4The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpupg-text...
CVE-2024-3648MEDIUM5.4The ShareThis Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sharethi...
CVE-2024-36013HIGH8.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_...
CVE-2024-36012HIGH7.8In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do...
CVE-2024-36011MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix potential null-ptr-deref Fix p...
CVE-2024-2874MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions before 16.10.6, version 16.11 before 16.11.3, and 17...
CVE-2024-2038HIGH7.5The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthori...
CVE-2024-5239MEDIUM6.5A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. ...
CVE-2024-5238MEDIUM6.5A vulnerability, which was classified as critical, was found in Campcodes Complete Web-Based School Management System 1....
CVE-2024-5237MEDIUM6.5A vulnerability, which was classified as critical, has been found in Campcodes Complete Web-Based School Management Syst...
CVE-2024-5177MEDIUM5.4The Hash Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter within multi...
CVE-2024-4399CRITICAL9.1The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSR...
CVE-2024-4388HIGH7.5This does not validate a path generated with user input when downloading files, allowing unauthenticated user to downlo...
CVE-2024-4347HIGH7.2The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2...
CVE-2024-3920LOW3.5The Flattr WordPress plugin through 1.2.2 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-3918MEDIUM4.8The Pet Manager WordPress plugin through 1.4 does not sanitise and escape some of its Pet settings, which could allow hi...
CVE-2024-3917MEDIUM6.1The Pet Manager WordPress plugin through 1.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-3711MEDIUM4.3The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized plugin setting update due to a missing capab...
CVE-2024-3626MEDIUM4.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-3594HIGH8.7The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-2220LOW3.5The Button contact VR WordPress plugin through 4.7 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-5236MEDIUM6.5A vulnerability classified as critical was found in Campcodes Complete Web-Based School Management System 1.0. Affected ...
CVE-2024-5235MEDIUM6.5A vulnerability classified as critical has been found in Campcodes Complete Web-Based School Management System 1.0. Affe...
CVE-2024-5234MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as critical. T...
CVE-2024-5233MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as critical...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now