2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13626HIGH7.1The VR-Frases (collect & share quotes) WordPress plugin through 3.0.1 does not sanitise and escape a parameter before ou...
CVE-2024-13625HIGH7.1The Tube Video Ads Lite WordPress plugin through 1.5.7 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-13608MEDIUM4.7The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statemen...
CVE-2024-13603MEDIUM6.1The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut...
CVE-2024-44044HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brandexponents Osh...
CVE-2024-57971CRITICAL9.1DataSourceResource.java in the SpagoBI API support in Knowage Server in KNOWAGE before 8.1.30 does not ensure that java:...
CVE-2024-57970MEDIUM4libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c v...
CVE-2024-13834MEDIUM5.4The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordP...
CVE-2024-13500MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-13488HIGH7.5The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' an...
CVE-2024-13439MEDIUM4.3The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2024-10581MEDIUM4.3The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-13752MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-12562CRITICAL9.8The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216...
CVE-2024-13563MEDIUM5.4The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s...
CVE-2024-13525MEDIUM6.5The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13513CRITICAL9.8The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2024-13306MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-13208MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-37375——Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13843.
CVE-2024-37374——Rejected reason: This CVE record has been withdrawn due to a duplicate entry CVE-2024-13842.
CVE-2024-5462HIGH7.5If Brocade Fabric OS before Fabric OS 9.2.0 configuration settings are not set to encrypt SNMP passwords, then the SNMP ...
CVE-2024-5461HIGH8Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch...
CVE-2024-4282CRITICAL9.8Brocade SANnav OVA before SANnav 2.3.1b enables SHA1 deprecated setting for SSH for port 22.
CVE-2024-10405MEDIUM5.3Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now