2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13240HIGH7.5Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issu...
CVE-2024-13239CRITICAL9.8Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affec...
CVE-2024-13238MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify a...
CVE-2024-13237MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity...
CVE-2024-10106LOW3.7A buffer overflow vulnerability in the packet handoff plugin allows an attacker to overwrite memory outside the plugin's...
CVE-2024-43176MEDIUM5.4IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should o...
CVE-2024-6155MEDIUM5.4The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Ser...
CVE-2024-5769MEDIUM4.3The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-12848HIGH8.8The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on t...
CVE-2024-12819MEDIUM6.4The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc...
CVE-2024-12621MEDIUM6.4The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' ...
CVE-2024-12618MEDIUM4.3The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-12616MEDIUM4.3The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-12605MEDIUM4.3The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-12542HIGH8.6The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when incl...
CVE-2024-12515MEDIUM6.4The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID ...
CVE-2024-12514MEDIUM6.4The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short...
CVE-2024-12496MEDIUM6.4The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi...
CVE-2024-12493MEDIUM6.4The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh...
CVE-2024-12491MEDIUM6.4The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se...
CVE-2024-12394MEDIUM6.1The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all ...
CVE-2024-12330HIGH7.5The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensit...
CVE-2024-12285MEDIUM6.1The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versi...
CVE-2024-12249MEDIUM4.3The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-12222MEDIUM6.1The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvs...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now