2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1582MEDIUM5.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-1421MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘b...
CVE-2024-1397MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-2395MEDIUM4.3The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2024-2107HIGH7.5The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2024-24101CRITICAL9.8Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
CVE-2024-0386MEDIUM6.1The weForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Referer' HTTP header in all versi...
CVE-2024-2406CRITICAL9.8A vulnerability, which was classified as critical, was found in Gacjie Server up to 1.0. This affects the function index...
CVE-2024-28239MEDIUM4.3Directus is a real-time API and App dashboard for managing SQL database content. The authentication API has a `redirect`...
CVE-2024-28238LOW2.3Directus is a real-time API and App dashboard for managing SQL database content. When reaching the /files page, a JWT is...
CVE-2024-28236MEDIUM6.5Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. Vela pipelines ca...
CVE-2024-27305MEDIUM5.3aiosmtpd is a reimplementation of the Python stdlib smtpd.py based on asyncio. aiosmtpd is vulnerable to inbound SMTP sm...
CVE-2024-24097MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary...
CVE-2024-24093CRITICAL9.8SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Per...
CVE-2024-24092HIGH7.8SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via...
CVE-2024-23300HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Process...
CVE-2024-2130MEDIUM5.4The CWW Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Module2 widget in all versio...
CVE-2024-2031MEDIUM5.4The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoo...
CVE-2024-28186HIGH7.1FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free ...
CVE-2024-28121HIGH8.8stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and ...
CVE-2024-28114CRITICAL9.1Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to ...
CVE-2024-28113MEDIUM6.1Peering Manager is a BGP session management tool. In Peering Manager <=1.8.2, it is possible to redirect users to an arb...
CVE-2024-28112MEDIUM4.8Peering Manager is a BGP session management tool. Affected versions of Peering Manager are subject to a potential stored...
CVE-2024-28098MEDIUM5.4The vulnerability allows authenticated users with only produce or consume permissions to modify topic-level policies, su...
CVE-2024-27894HIGH8.8The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now