2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32520 | MEDIUM | 4.3 | 0.3% | Apr 17, 2024 | Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Produ... |
| CVE-2024-32519 | MEDIUM | 4.3 | 0.3% | Apr 17, 2024 | Missing Authorization vulnerability in GutenGeek GG Woo Feed for WooCommerce.This issue affects GG Woo Feed for WooComme... |
| CVE-2024-32518 | MEDIUM | 5.3 | 0.4% | Apr 17, 2024 | Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate I... |
| CVE-2024-32517 | MEDIUM | 4.3 | 0.3% | Apr 17, 2024 | Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce... |
| CVE-2024-32516 | MEDIUM | 4.3 | 0.5% | Apr 17, 2024 | Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For Woo... |
| CVE-2024-32515 | MEDIUM | 5.4 | 0.4% | Apr 17, 2024 | Missing Authorization vulnerability in Qamar Sheeraz, Nasir Ahmad Mega Addons For Elementor.This issue affects Mega Addo... |
| CVE-2024-32514 | CRITICAL | 9.9 | 0.7% | Apr 17, 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Mak... |
| CVE-2024-32513 | MEDIUM | 5.3 | 0.4% | Apr 17, 2024 | Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issu... |
| CVE-2024-32509 | MEDIUM | 6.5 | 0.4% | Apr 17, 2024 | Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Esti... |
| CVE-2024-32506 | MEDIUM | 5.4 | 0.4% | Apr 17, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radi... |
| CVE-2024-22440 | MEDIUM | 6.8 | 0.4% | Apr 17, 2024 | A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability c... |
| CVE-2024-2309 | MEDIUM | 4.8 | 0.4% | Apr 17, 2024 | The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does... |
| CVE-2024-2118 | MEDIUM | 5.9 | 0.4% | Apr 17, 2024 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of... |
| CVE-2024-2102 | MEDIUM | 4.7 | 0.5% | Apr 17, 2024 | The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field an... |
| CVE-2024-2101 | MEDIUM | 5.7 | 0.6% | Apr 17, 2024 | The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field wh... |
| CVE-2024-1219 | MEDIUM | 5.3 | 0.3% | Apr 17, 2024 | The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before... |
| CVE-2024-0868 | MEDIUM | 5.3 | 0.5% | Apr 17, 2024 | The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers... |
| CVE-2024-22329 | MEDIUM | 4.3 | 0.3% | Apr 17, 2024 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vul... |
| CVE-2024-22354 | HIGH | 7 | 0.6% | Apr 17, 2024 | IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vul... |
| CVE-2024-31680 | HIGH | 8.8 | 0.8% | Apr 17, 2024 | File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a loc... |
| CVE-2024-31503 | HIGH | 7.5 | 0.3% | Apr 17, 2024 | Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim ... |
| CVE-2024-31760 | MEDIUM | 4.7 | 0.5% | Apr 16, 2024 | An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges via the Session Expirat... |
| CVE-2024-31759 | HIGH | 8.8 | 0.9% | Apr 16, 2024 | An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function. |
| CVE-2024-29402 | MEDIUM | 4.3 | 0.5% | Apr 16, 2024 | cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious ... |
| CVE-2024-29291 | — | — | 1.3% | Apr 16, 2024 | An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now