2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4553MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-4435HIGH7.5When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered...
CVE-2024-4875MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss...
CVE-2024-4566HIGH7.1The ShopLentor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-3345MEDIUM5.4The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortc...
CVE-2024-4710MEDIUM6.4The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_m...
CVE-2024-4470MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-4442CRITICAL9.1The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and includ...
CVE-2024-4372MEDIUM5.4The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users...
CVE-2024-4290HIGH7.1The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could all...
CVE-2024-4289MEDIUM6.1The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting ...
CVE-2024-4061MEDIUM4.8The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-2189MEDIUM6.1The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget...
CVE-2024-4943MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in a...
CVE-2024-3155MEDIUM6.4The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre...
CVE-2024-0816MEDIUM5.5The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local a...
CVE-2024-5145HIGH8.8A vulnerability was found in SourceCodester Vehicle Management System up to 1.0 and classified as critical. This issue a...
CVE-2024-4985CRITICAL9.8An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sig...
CVE-2024-34710HIGH7.1Wiki.js is al wiki app built on Node.js. Client side template injection was discovered, that could allow an attacker to ...
CVE-2024-35195MEDIUM5.6Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is ...
CVE-2024-35194MEDIUM5.3Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial o...
CVE-2024-35192MEDIUM5.5Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images fro...
CVE-2024-35191MEDIUM4.4Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include mali...
CVE-2024-33901MEDIUM6.5Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in t...
CVE-2024-33900MEDIUM6.5KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now