2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11335MEDIUM6.4The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable t...
CVE-2024-13799MEDIUM6.4The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to S...
CVE-2024-12173LOW3.5The Master Slider WordPress plugin before 3.10.5 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-13443MEDIUM6.4The Easypromos Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Easypromos shor...
CVE-2024-11582HIGH7.2The Subscribe2 – Form, Email Subscribers & Newsletters plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-57262HIGH7.1In barebox before 2025.01.0, ext4fs_read_symlink has an integer overflow for zalloc (adding one to an le32 variable) via...
CVE-2024-57261HIGH7.1In barebox before 2025.01.0, request2size in common/dlmalloc.c has an integer overflow, a related issue to CVE-2024-5725...
CVE-2024-13508MEDIUM6.1The Booking Package plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the locale parameter in all...
CVE-2024-57259MEDIUM6.8sqfs_search_dir in Das U-Boot before 2025.01-rc1 exhibits an off-by-one error and resultant heap memory corruption for s...
CVE-2024-57258HIGH7.8Integer overflows in memory allocation in Das U-Boot before 2025.01-rc1 occur for a crafted squashfs filesystem via sbrk...
CVE-2024-57257LOW2.4A stack consumption issue in sqfs_size in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem with de...
CVE-2024-57256MEDIUM6.8An integer overflow in ext4fs_read_symlink in Das U-Boot before 2025.01-rc1 occurs for zalloc (adding one to an le32 var...
CVE-2024-57255MEDIUM6.8An integer overflow in sqfs_resolve_symlink in Das U-Boot before 2025.01-rc1 occurs via a crafted squashfs filesystem wi...
CVE-2024-57254MEDIUM6.8An integer overflow in sqfs_inode_size in Das U-Boot before 2025.01-rc1 occurs in the symlink size calculation via a cra...
CVE-2024-13743MEDIUM6.4The Wonder Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wonderplugin_v...
CVE-2024-56171CRITICAL9.8libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleID...
CVE-2024-56000CRITICAL9.8Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issu...
CVE-2024-45783MEDIUM4.4A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERR...
CVE-2024-45781MEDIUM6.7A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string...
CVE-2024-45776MEDIUM6.7When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its ...
CVE-2024-45775MEDIUM5.2A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for...
CVE-2024-57056MEDIUM5.4Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to sys...
CVE-2024-57055MEDIUM5Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potential...
CVE-2024-45774MEDIUM6.7A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bou...
CVE-2024-56883HIGH8.1Sage DPW before 2024_12_001 is vulnerable to Incorrect Access Control. The implemented role-based access controls are no...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now