2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3556Rejected reason: Duplicate of CVE-2024-3557
CVE-2024-3446HIGH8.2A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the m...
CVE-2024-27665MEDIUM5.4Unifiedtransform v2.X is vulnerable to Stored Cross-Site Scripting (XSS) via file upload feature in Syllabus module.
CVE-2024-3545MEDIUM4.3Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earl...
CVE-2024-3514Rejected reason: **DUPLICATE** Please use CVE-2024-1846 instead.
CVE-2024-3512Rejected reason: **DUPLICATE*** Please use CVE-2024-2583 instead.
CVE-2024-3267MEDIUM5.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_price_lis...
CVE-2024-3266MEDIUM5.4The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of widgets...
CVE-2024-3244MEDIUM5.4The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-3214CRITICAL9.8The Relevanssi – A Better Search plugin for WordPress is vulnerable to CSV Injection in all versions up to, and includin...
CVE-2024-3213HIGH8.2The Relevanssi – A Better Search plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2024-3208MEDIUM5.4The Sydney Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery...
CVE-2024-3167MEDIUM6.4The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘twitter_username’ parameter i...
CVE-2024-3136CRITICAL9.8The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3...
CVE-2024-3097MEDIUM5.3The WordPress Gallery Plugin – NextGEN Gallery plugin for WordPress is vulnerable to unauthorized access of data due to ...
CVE-2024-3093Rejected reason: ** DUPLICATE ** Accidental request. Please use CVE-2024-1752 instead.
CVE-2024-3064MEDIUM6.4The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-3053MEDIUM5.4The Forminator – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Sit...
CVE-2024-30706Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-2974MEDIUM5.3The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-2957Rejected reason: **DUPLICATE*** Please use CVE-2024-1983 instead.
CVE-2024-2946MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-2918LOW3.6Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker wit...
CVE-2024-2871HIGH7.7The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver...
CVE-2024-2866Rejected reason: ** REJECT ** Accidental reservation. Please use CVE-2024-2509.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now