2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13639MEDIUM4.3The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a miss...
CVE-2024-47266LOW2.7Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list function...
CVE-2024-47265MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount f...
CVE-2024-47264MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functional...
CVE-2024-13346CRITICAL9.8The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode executi...
CVE-2024-13345CRITICAL9.8The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and includi...
CVE-2024-13125LOW3.5The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-13121LOW3.5The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-13120MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-13119MEDIUM4.8The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl...
CVE-2024-12586MEDIUM6.1The Chalet-Montagne.com Tools WordPress plugin through 2.7.8 does not sanitise and escape a parameter before outputting ...
CVE-2024-10083MEDIUM6.8CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation whe...
CVE-2024-13770CRITICAL9.8The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to PHP Object Inje...
CVE-2024-13229MEDIUM4.3The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized loss of dat...
CVE-2024-13227MEDIUM5.4The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-10763CRITICAL9.8The Campress theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.35 via th...
CVE-2024-13644MEDIUM5.4The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's De Galle...
CVE-2024-8266MEDIUM6.6An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attac...
CVE-2024-7102HIGH7.5An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attack...
CVE-2024-51376HIGH7.5Directory Traversal vulnerability in yeqifu carRental v.1.0 allows a remote attacker to obtain sensitive information via...
CVE-2024-34521LOW3.5A directory traversal vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_...
CVE-2024-34520HIGH8.8An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_...
CVE-2024-57605MEDIUM5.4Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the...
CVE-2024-57604CRITICAL9.8An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.
CVE-2024-57603MEDIUM6.3An issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the lack of rate limiting.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now