2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50687CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50686CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) vi...
CVE-2024-50685CRITICAL9.1SunGrow iSolarCloud before the October 31, 2024 remediation, is vulnerable to insecure direct object references (IDOR) v...
CVE-2024-50684MEDIUM6.5SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient ...
CVE-2024-53427HIGH8.1decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which ha...
CVE-2024-46226MEDIUM4.8A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary Jav...
CVE-2024-52925MEDIUM6.8In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unl...
CVE-2024-6810MEDIUM4.4The Quiz Organizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includin...
CVE-2024-47053HIGH7.7This advisory addresses an authorization vulnerability in Mautic's HTTP Basic Authentication implementation. This flaw c...
CVE-2024-47051CRITICAL9.9This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili...
CVE-2024-39441HIGH8.4In wifi display, there is a possible missing permission check. This could lead to local escalation of privilege with no ...
CVE-2024-13803MEDIUM5.4The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2024-13678MEDIUM6.1The R3W InstaFeed WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13669MEDIUM6.1The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13634MEDIUM6.1The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13633HIGH7.1The Simple catalogue WordPress plugin through 1.0.2 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13632HIGH7.1The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13631HIGH7.1The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in th...
CVE-2024-13630MEDIUM6.1The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13629MEDIUM6.1The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-13628MEDIUM6.1The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-13624HIGH7.1The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-13571HIGH7.1The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13560MEDIUM4.3The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2024-13113MEDIUM5.9The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when output...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now