2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0839MEDIUM5.3The FeedWordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl...
CVE-2024-0830MEDIUM4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2024-0829MEDIUM4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all vers...
CVE-2024-0828MEDIUM6.3The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to unauthoriz...
CVE-2024-0827MEDIUM4.3The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to Cross-Site...
CVE-2024-0700MEDIUM5.4The Simple Tweet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tweet this text value in all ...
CVE-2024-0687MEDIUM5.3The Restrict User Access – Ultimate Membership & Content Protection plugin for WordPress is vulnerable to Information Ex...
CVE-2024-0683HIGH7.5The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability ch...
CVE-2024-0681MEDIUM5.3The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure...
CVE-2024-0631MEDIUM5.3The Duitku Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capa...
CVE-2024-0614MEDIUM4.8The Events Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ...
CVE-2024-0592MEDIUM5.4The Related Posts for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ...
CVE-2024-0591MEDIUM6.1The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to Refl...
CVE-2024-0449MEDIUM4.8The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a...
CVE-2024-0447MEDIUM5The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-0385MEDIUM4.3The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0377MEDIUM5.3The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-0369MEDIUM4.3The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2024-0368HIGH8.6The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Informatio...
CVE-2024-0326MEDIUM6.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link...
CVE-2024-0161HIGH8.4Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulner...
CVE-2024-27441Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-25155MEDIUM6.1In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in ...
CVE-2024-25154MEDIUM5.3Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to ...
CVE-2024-25153CRITICAL9.8A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outsid...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now