2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31025HIGH7.5SQL Injection vulnerability in ECshop 4.x allows an attacker to obtain sensitive information via the file/article.php co...
CVE-2024-2919MEDIUM5.4The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-2830MEDIUM6.4The WordPress Tag and Category Manager – AI Autotagger plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-2008HIGH8.8The Modal Popup Box – Popup Builder, Show Offers And News in Popup plugin for WordPress is vulnerable to PHP Object Inje...
CVE-2024-3274MEDIUM5.3** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in D-Link DNS-320L, DNS-320LW and DNS-327L up to 20240403...
CVE-2024-3030MEDIUM4.4The Announce from the Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in ...
CVE-2024-3022HIGH7.2The BookingPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient filename validation in...
CVE-2024-2868MEDIUM6.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-2803MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown wid...
CVE-2024-2692CRITICAL9SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vuln...
CVE-2024-3273CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325...
CVE-2024-3272CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320...
CVE-2024-29225MEDIUM4.3ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containin...
CVE-2024-29167HIGH7.2SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execu...
CVE-2024-26258HIGH7.1OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to...
CVE-2024-25568HIGH8.8OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to ...
CVE-2024-3270MEDIUM6.5A vulnerability classified as problematic was found in ThingsBoard up to 3.6.2. This vulnerability affects unknown code ...
CVE-2024-30265HIGH7.5Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboa...
CVE-2024-2689MEDIUM4.4Denial of Service in Temporal Server prior to version 1.20.5, 1.21.6, and 1.22.7 allows an authenticated user who has pe...
CVE-2024-29413MEDIUM5.4Cross Site Scripting vulnerability in Webasyst v.2.9.9 allows a remote attacker to run arbitrary code via the Instant me...
CVE-2024-28870HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine dev...
CVE-2024-27705HIGH7.6Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted P...
CVE-2024-27706MEDIUM6.1Cross Site Scripting vulnerability in Huly Platform v.0.6.202 allows attackers to execute arbitrary code via upload of c...
CVE-2024-3181MEDIUM4.8Concrete CMS version 9 prior to 9.2.8 and previous versions prior to 8.5.16 are vulnerable to Stored XSS in the Search F...
CVE-2024-3180MEDIUM4.8Concrete CMS version 9 below 9.2.8 and previous versions below 8.5.16 is vulnerable to Stored XSS in blocks of type file...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now