2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1308HIGH7.5The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a m...
CVE-2024-1289MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers...
CVE-2024-0952HIGH7.2The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-0899MEDIUM5.3The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscri...
CVE-2024-0873MEDIUM5.4The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shor...
CVE-2024-0872MEDIUM4.3The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2024-0826MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets i...
CVE-2024-0662MEDIUM4.8The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi...
CVE-2024-0626MEDIUM5.3The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-0598MEDIUM4.8The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-0588MEDIUM4.3The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab...
CVE-2024-0376MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrap...
CVE-2024-31507HIGH8.6Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fe...
CVE-2024-31506HIGH7.5Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_c...
CVE-2024-31457HIGH7.7gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac...
CVE-2024-31454MEDIUM6.5PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on...
CVE-2024-31453MEDIUM6.5PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on...
CVE-2024-30704Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30703Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-30702Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-27247MEDIUM6.7Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a priv...
CVE-2024-27242MEDIUM6.8Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct ...
CVE-2024-25116MEDIUM5.5RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 an...
CVE-2024-25115HIGH7RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 an...
CVE-2024-24694HIGH7.8Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now