2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53681MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvmet: Don't overflow subsysnqn nvmet_root_discove...
CVE-2024-39282MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: wwan: t7xx: Fix FSM command timeout issue Whe...
CVE-2024-36476MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move...
CVE-2024-13215MEDIUM4.3The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-11029MEDIUM5.5A flaw was found in the FreeIPA API audit, where it sends the whole FreeIPA command line to journalctl. As a consequence...
CVE-2024-12593MEDIUM6.4The PDF for WPForms + Drag and Drop Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-11851MEDIUM4.3The NitroPack plugin for WordPress is vulnerable to unauthorized arbitrary transient update due to a missing capability ...
CVE-2024-11848HIGH8.1The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-35280MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDe...
CVE-2024-9636CRITICAL9.8The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in versions 2.2.85 to 2.3....
CVE-2024-13351HIGH7.2The Social proof testimonials and reviews by Repuso plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-12818MEDIUM6.4The WP Smart TV plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tv-video-player' sho...
CVE-2024-12423MEDIUM6.1The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-12403MEDIUM6.1The Image Gallery – Responsive Photo Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-12297CRITICAL9.2Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Althou...
CVE-2024-10775MEDIUM4.3The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-7322MEDIUM5.8A ZigBee coordinator, router, or end device may change their node ID when an unsolicited encrypted rejoin response is re...
CVE-2024-4227HIGH7.5In Genivia gSOAP with a specific configuration an unauthenticated remote attacker can generate a high CPU load when forc...
CVE-2024-11870MEDIUM6.4The Event Registration Calendar By vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-55577HIGH7Stack-based buffer overflow vulnerability exists in Linux Ratfor 1.06 and earlier. When the software processes a file wh...
CVE-2024-13394MEDIUM6.4The ViewMedica 9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewmedica' shortco...
CVE-2024-13334MEDIUM6.1The Car Demon plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_condition' parameter ...
CVE-2024-57767HIGH8.6MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CVE-2024-57766CRITICAL9.1MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table...
CVE-2024-57765HIGH7.5MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now