2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13770CRITICAL9.8The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje...
CVE-2024-13229MEDIUM4.3The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of dat...
CVE-2024-13227MEDIUM5.4The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-10763CRITICAL9.8The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th...
CVE-2024-13644MEDIUM5.4The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Galle...
CVE-2024-8266MEDIUM6.6An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attac...
CVE-2024-7102HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attack...
CVE-2024-51376HIGH7.5Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via...
CVE-2024-34521LOW3.5A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_...
CVE-2024-34520HIGH8.8An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_...
CVE-2024-57605MEDIUM5.4Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the...
CVE-2024-57604CRITICAL9.8An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
CVE-2024-57603MEDIUM6.3An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.
CVE-2024-57602CRITICAL9.8An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php f...
CVE-2024-57601MEDIUM6.1Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbit...
CVE-2024-56940HIGH7.5An issue in the profile image upload function of LearnDash v6.7.1 allows attackers to cause a Denial of Service (DoS) vi...
CVE-2024-56939MEDIUM5.4LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the ld-comment-body clas...
CVE-2024-56938MEDIUM5.4LearnDash v6.7.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the materials-content cl...
CVE-2024-51440HIGH7.8An issue in Nothing Tech Nothing OS v.2.6 allows a local attacker to escalate privileges via the NtBpfService component.
CVE-2024-51123HIGH7.5An issue in Zertificon Z1 SecureMail Z1 SecureMail Gateway 4.44.2-7240-debian12 allows a remote attacker to obtain sensi...
CVE-2024-51122MEDIUM6.1Cross Site Scripting vulnerability in Zertificon Z1 SecureMail Z1 CertServer v.3.16.4-2516-debian12 alllows a remote att...
CVE-2024-47006MEDIUM6.7Uncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 1...
CVE-2024-46923HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. The absence of a null check leads to a ...
CVE-2024-46922HIGH7.5An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The absence of a null check leads to a Denial ...
CVE-2024-42492MEDIUM6.7Uncontrolled search path element in some BIOS and System Firmware Update Package for Intel(R) Server M50FCP family befor...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now