2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-24771MEDIUM5.9Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-e...
CVE-2024-25201HIGH7.5Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at sr...
CVE-2024-25200HIGH7.5Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse....
CVE-2024-24189CRITICAL9.8Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.
CVE-2024-24188CRITICAL9.8Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.
CVE-2024-24186CRITICAL9.8Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish...
CVE-2024-24133CRITICAL9.8Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.
CVE-2024-24131MEDIUM6.1SuperWebMailer v9.31.0.01799 was discovered to contain a reflected cross-site scripting (XSS) vulenrability via the comp...
CVE-2024-24130MEDIUM6.1Mail2World v12 Business Control Center was discovered to contain a reflected cross-site scripting (XSS) vulnerability vi...
CVE-2024-1118HIGH8.8The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute ...
CVE-2024-1110MEDIUM5.3The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-1109MEDIUM5.3The Podlove Podcast Publisher plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil...
CVE-2024-24311HIGH7.5Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for Pr...
CVE-2024-24304HIGH7.5In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical info...
CVE-2024-24303CRITICAL9.8SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before versio...
CVE-2024-1079MEDIUM5.3The Quiz Maker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-1078MEDIUM4.3The Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0977MEDIUM5.4The Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) plugin for WordPress is vulnerabl...
CVE-2024-1055MEDIUM5.4The PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored...
CVE-2024-1037MEDIUM6.1The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-0628LOW3.8The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2024-0256MEDIUM5.4The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Se...
CVE-2024-23447MEDIUM6.5An issue was discovered in the Windows Network Drive Connector when using Document Level Security to assign permissions ...
CVE-2024-23446MEDIUM6.5An issue was discovered by Elastic, whereby the Detection Engine Search API does not respect Document-level security (DL...
CVE-2024-24810HIGH7.8WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folde...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now