2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4662HIGH8.8The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8...
CVE-2024-5232MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as critic...
CVE-2024-4431MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ p...
CVE-2024-5231MEDIUM6.5A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as critical. Affec...
CVE-2024-4895MEDIUM4.7The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Stor...
CVE-2024-5230MEDIUM6.9A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic. Affected by this vulner...
CVE-2024-4978HIGH8.4Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected...
CVE-2024-4783MEDIUM6.4The jQuery T(-) Countdown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's tmin...
CVE-2024-4486MEDIUM6.4The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'AEP C...
CVE-2024-3201MEDIUM6.4The WP DSGVO Tools (GDPR) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pp_link' s...
CVE-2024-3065MEDIUM4.4The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-1855MEDIUM5.3The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table Reservation plugin for WordPr...
CVE-2024-3708Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-29853HIGH7.8An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
CVE-2024-29852LOW2.7Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
CVE-2024-29851HIGH7.2Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
CVE-2024-29850HIGH8.8Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
CVE-2024-29849CRITICAL9.8Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
CVE-2024-22026MEDIUM6.7A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell re...
CVE-2024-4454HIGH7.8WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allo...
CVE-2024-4453HIGH7.8GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2024-4267CRITICAL9.8A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' mod...
CVE-2024-31895MEDIUM6.5IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user informa...
CVE-2024-31894MEDIUM4.3IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user informa...
CVE-2024-27264HIGH7.8IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqual...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now