2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-1308 | HIGH | 7.5 | 0.7% | Apr 9, 2024 | The WooCommerce Cloak Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a m... |
| CVE-2024-1289 | MEDIUM | 5.4 | 0.4% | Apr 9, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all vers... |
| CVE-2024-0952 | HIGH | 7.2 | 0.9% | Apr 9, 2024 | The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is... |
| CVE-2024-0899 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The s2Member – Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscri... |
| CVE-2024-0873 | MEDIUM | 5.4 | 0.5% | Apr 9, 2024 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'watu-basic-chart' shor... |
| CVE-2024-0872 | MEDIUM | 4.3 | 0.5% | Apr 9, 2024 | The Watu Quiz plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2024-0826 | MEDIUM | 5.4 | 0.6% | Apr 9, 2024 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets i... |
| CVE-2024-0662 | MEDIUM | 4.8 | 0.5% | Apr 9, 2024 | The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versi... |
| CVE-2024-0626 | MEDIUM | 5.3 | 0.6% | Apr 9, 2024 | The WooCommerce Clover Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-0598 | MEDIUM | 4.8 | 0.7% | Apr 9, 2024 | The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2024-0588 | MEDIUM | 4.3 | 0.9% | Apr 9, 2024 | The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerab... |
| CVE-2024-0376 | MEDIUM | 5.4 | 0.7% | Apr 9, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Wrap... |
| CVE-2024-31507 | HIGH | 8.6 | 0.5% | Apr 9, 2024 | Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fe... |
| CVE-2024-31506 | HIGH | 7.5 | 0.7% | Apr 9, 2024 | Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_c... |
| CVE-2024-31457 | HIGH | 7.7 | 0.9% | Apr 9, 2024 | gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac... |
| CVE-2024-31454 | MEDIUM | 6.5 | 0.5% | Apr 9, 2024 | PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on... |
| CVE-2024-31453 | MEDIUM | 6.5 | 0.5% | Apr 9, 2024 | PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of restrictions on... |
| CVE-2024-30704 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30703 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-30702 | — | — | — | Apr 9, 2024 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2024-27247 | MEDIUM | 6.7 | 0.1% | Apr 9, 2024 | Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a priv... |
| CVE-2024-27242 | MEDIUM | 6.8 | 0.5% | Apr 9, 2024 | Cross site scripting in Zoom Desktop Client for Linux before version 5.17.10 may allow an authenticated user to conduct ... |
| CVE-2024-25116 | MEDIUM | 5.5 | 0.2% | Apr 9, 2024 | RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 an... |
| CVE-2024-25115 | HIGH | 7 | 0.4% | Apr 9, 2024 | RedisBloom adds a set of probabilistic data structures to Redis. Starting in version 2.0.0 and prior to version 2.4.7 an... |
| CVE-2024-24694 | HIGH | 7.8 | 0.2% | Apr 9, 2024 | Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an a... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now