2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-23488MEDIUM4.3Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members...
CVE-2024-1887MEDIUM4.3Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is...
CVE-2024-25594MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress De...
CVE-2024-25292CRITICAL9.6Cross-site scripting (XSS) vulnerability in RenderTune v1.1.4 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2024-25291CRITICAL9.8Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
CVE-2024-1982CRITICAL9.1The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to unauthorized access due to a missing capa...
CVE-2024-1981CRITICAL9.1The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' para...
CVE-2024-1978MEDIUM5.5The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8....
CVE-2024-25098MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB ...
CVE-2024-25094MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicola...
CVE-2024-25093MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD ...
CVE-2024-24525CRITICAL9.8An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code vi...
CVE-2024-23501MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Eboo...
CVE-2024-21752MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affe...
CVE-2024-1977MEDIUM4.8The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist...
CVE-2024-1976MEDIUM4.3The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2024-1437MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Ads...
CVE-2024-1434MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Media A...
CVE-2024-1435HIGH7.5Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainaca...
CVE-2024-1341MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe s...
CVE-2024-1468HIGH8.8The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due ...
CVE-2024-0689MEDIUM4.8The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versio...
CVE-2024-22871HIGH7.5An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure...
CVE-2024-27517MEDIUM5.4Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code afte...
CVE-2024-27516CRITICAL9.8Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now