2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32520MEDIUM4.3Missing Authorization vulnerability in WPClever WPC Grouped Product for WooCommerce.This issue affects WPC Grouped Produ...
CVE-2024-32519MEDIUM4.3Missing Authorization vulnerability in GutenGeek GG Woo Feed for WooCommerce.This issue affects GG Woo Feed for WooComme...
CVE-2024-32518MEDIUM5.3Missing Authorization vulnerability in Pepro Dev. Group PeproDev Ultimate Invoice.This issue affects PeproDev Ultimate I...
CVE-2024-32517MEDIUM4.3Missing Authorization vulnerability in WooCommerce & WordPress Tutorials Custom Thank You Page Customize For WooCommerce...
CVE-2024-32516MEDIUM4.3Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For Woo...
CVE-2024-32515MEDIUM5.4Missing Authorization vulnerability in Qamar Sheeraz, Nasir Ahmad Mega Addons For Elementor.This issue affects Mega Addo...
CVE-2024-32514CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Mak...
CVE-2024-32513MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issu...
CVE-2024-32509MEDIUM6.5Missing Authorization vulnerability in Loopus WP Cost Estimation & Payment Forms Builder.This issue affects WP Cost Esti...
CVE-2024-32506MEDIUM5.4Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radi...
CVE-2024-22440MEDIUM6.8 A potential security vulnerability has been identified in HPE Compute Scale-up Server 3200 server. This vulnerability c...
CVE-2024-2309MEDIUM4.8The WP STAGING WordPress Backup Plugin WordPress plugin before 3.4.0, wp-staging-pro WordPress plugin before 5.4.0 does...
CVE-2024-2118MEDIUM5.9The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.8.9 does not sanitise and escape some of...
CVE-2024-2102MEDIUM4.7The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field an...
CVE-2024-2101MEDIUM5.7The Salon booking system WordPress plugin before 9.6.3 does not properly sanitize and escape the 'Mobile Phone' field wh...
CVE-2024-1219MEDIUM5.3The Easy Social Feed WordPress plugin before 6.5.6 does not validate and escape some of its shortcode attributes before...
CVE-2024-0868MEDIUM5.3The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers...
CVE-2024-22329MEDIUM4.3IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.3 are vul...
CVE-2024-22354HIGH7IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vul...
CVE-2024-31680HIGH8.8File Upload vulnerability in Shibang Communications Co., Ltd. IP network intercom broadcasting system v.1.0 allows a loc...
CVE-2024-31503HIGH7.5Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim ...
CVE-2024-31760MEDIUM4.7An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges via the Session Expirat...
CVE-2024-31759HIGH8.8An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
CVE-2024-29402MEDIUM4.3cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious ...
CVE-2024-29291An issue in Laravel Framework 8 through 11 might allow a remote attacker to discover database credentials in storage/log...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now