2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24868HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Pro...
CVE-2024-21886HIGH7.8A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an appli...
CVE-2024-21885HIGH7.8A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated arr...
CVE-2024-1965MEDIUM5.3Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could ...
CVE-2024-1808MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-26016MEDIUM5.4A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then ...
CVE-2024-24779MEDIUM6.5Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows fo...
CVE-2024-24773MEDIUM6.5Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization ...
CVE-2024-24772MEDIUM4.3A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information ...
CVE-2024-1636MEDIUM5.4Potential Cross-Site Scripting (XSS) in the page editing area.
CVE-2024-1632MEDIUM6.5Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrati...
CVE-2024-27315MEDIUM4.3An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially cr...
CVE-2024-1861MEDIUM4.3The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v...
CVE-2024-1860MEDIUM5.3The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is v...
CVE-2024-1719MEDIUM4.3The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2024-22459MEDIUM6.5Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper a...
CVE-2024-1954MEDIUM6.3The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-1791MEDIUM5.4The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all...
CVE-2024-1566MEDIUM6.5The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-1516MEDIUM5.3The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability ...
CVE-2024-1514HIGH7.5The WP eCommerce plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'cart_contents' parameter ...
CVE-2024-1476MEDIUM5.3The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2024-1368MEDIUM5.3The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-1136MEDIUM5.3The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an impr...
CVE-2024-0975MEDIUM5.3The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now