2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0740CRITICAL9.8Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vuln...
CVE-2024-4198LOW2.7Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows ...
CVE-2024-4195LOW2.7Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows...
CVE-2024-4183MEDIUM6.5Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the nu...
CVE-2024-4182MEDIUM4.3Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing e...
CVE-2024-3962CRITICAL9.8The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing ...
CVE-2024-32046MEDIUM4.3Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error mes...
CVE-2024-22091MEDIUM6.5Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a requ...
CVE-2024-1789HIGH7.2The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due ...
CVE-2024-3890MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget...
CVE-2024-3678MEDIUM5.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2024-33651HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Matthew Fries MF Gig Calendar.This issue affects MF Gig Calendar : fr...
CVE-2024-33650MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: fr...
CVE-2024-33642MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Pos...
CVE-2024-33639MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAl...
CVE-2024-33638MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maint...
CVE-2024-33598MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annua...
CVE-2024-2920MEDIUM5.3The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-4056HIGH7.5Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allow...
CVE-2024-3188MEDIUM6.3The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its sh...
CVE-2024-3075HIGH8.1The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before o...
CVE-2024-3060MEDIUM4.5The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL stat...
CVE-2024-3059MEDIUM5.7The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers ...
CVE-2024-3058MEDIUM5.4The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-3048MEDIUM5.5The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leadin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now