2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3680MEDIUM5.4The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scrip...
CVE-2024-3595MEDIUM6.4The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purec...
CVE-2024-3590MEDIUM6.1The LetterPress WordPress plugin through 1.2.2 does not have CSRF checks in some places, which could allow attackers to...
CVE-2024-3582MEDIUM4.8The UnGallery WordPress plugin through 2.2.4 does not have CSRF check in some places, and is missing sanitisation as wel...
CVE-2024-3547MEDIUM6.1The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected C...
CVE-2024-3462MEDIUM5.4Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorizati...
CVE-2024-3461MEDIUM5.5KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application fro...
CVE-2024-3460HIGH7In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened app...
CVE-2024-3459HIGH7.8KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by...
CVE-2024-3263CRITICAL9.8YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combinatio...
CVE-2024-3239MEDIUM5.4The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape som...
CVE-2024-3070CRITICAL9.8The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, an...
CVE-2024-3068MEDIUM4.8The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' ...
CVE-2024-3055HIGH8.8The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based ...
CVE-2024-3037HIGH7.8An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print...
CVE-2024-3016CRITICAL9.1NEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5.4.0.0 – v5.6.0.20 allows an attacker to access a non-docume...
CVE-2024-35205HIGH7.8The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names befo...
CVE-2024-35204HIGH8.4Veritas System Recovery before 23.3_Hotfix has incorrect permissions for the Veritas System Recovery folder, and thus lo...
CVE-2024-35172MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.Thi...
CVE-2024-35171MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Acade...
CVE-2024-35170MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Stick...
CVE-2024-35169MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_bloc...
CVE-2024-35167MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's ...
CVE-2024-35166HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team Filebird.This issue affects Fileb...
CVE-2024-35165MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now