2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13368MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-12885MEDIUM6.5The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficien...
CVE-2024-12826MEDIUM4.3The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due ...
CVE-2024-12817MEDIUM6.4The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shor...
CVE-2024-12816MEDIUM6.4The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-bo...
CVE-2024-12529MEDIUM6.4The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Bro...
CVE-2024-12512MEDIUM6.4The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'as...
CVE-2024-12113MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-12076MEDIUM6.1The Target Video Easy Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an...
CVE-2024-11825MEDIUM6.4The Broadstreet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘zone’ parameter in all versio...
CVE-2024-12600HIGH7.2The Custom Product Tabs Lite for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions ...
CVE-2024-10552MEDIUM6.4The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘api_key’ and 'api_sec...
CVE-2024-13721MEDIUM6.4The Plethora Plugins Tabs + Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the anchor ...
CVE-2024-13709MEDIUM4.3The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1....
CVE-2024-50698CRITICAL9.8SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to heap-based buffer overflow due to bounds checks of...
CVE-2024-50697HIGH8.1In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TL...
CVE-2024-50695CRITICAL9.8SunGrow WiNet-SV200.001.00.P027 and earlier versions is vulnerable to stack-based buffer overflow when parsing MQTT mess...
CVE-2024-50694CRITICAL9.8In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when copying the timestamp read from an MQTT message, the under...
CVE-2024-50692MEDIUM5.4SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that allow an attacker to send ...
CVE-2024-50690MEDIUM6.5SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be used to decrypt all firmw...
CVE-2024-57277MEDIUM5.7InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2024-57095MEDIUM6.8SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-57041MEDIUM4.6A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code ...
CVE-2024-52807HIGH8.6The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT ...
CVE-2024-56404CRITICAL9.9In One Identity Identity Manager 9.x before 9.3, an insecure direct object reference (IDOR) vulnerability allows privile...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now