2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12275MEDIUM6.1The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-11886MEDIUM6.4The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-10867MEDIUM5.4The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable t...
CVE-2024-47900HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to access OOB kernel memory.
CVE-2024-47899HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-47898HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-47891HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern...
CVE-2024-13463MEDIUM6.4The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in al...
CVE-2024-46974HIGH7.8Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA ...
CVE-2024-13817Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2024-13767HIGH8.1The Live2DWebCanvas plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati...
CVE-2024-13399MEDIUM6.4The Gosign – Posts Slider Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'posts-slider-...
CVE-2024-13397MEDIUM6.4The WPRadio – WordPress Radio Streaming Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-13396MEDIUM6.4The Frictionless plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'frictionless_form' ...
CVE-2024-23929HIGH7.3This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-...
CVE-2024-23921HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-23920HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-24731HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs...
CVE-2024-23973HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Silicon Labs...
CVE-2024-23971HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-23970MEDIUM6.5This vulnerability allows network-adjacent attackers to compromise transport security on affected installations of Charg...
CVE-2024-23969HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-23968HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint ...
CVE-2024-23963HIGH8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9...
CVE-2024-23962MEDIUM5.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now