2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12218MEDIUM6.1The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12206MEDIUM4.3The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-12122MEDIUM6.1The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions ...
CVE-2024-12067MEDIUM6.5The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injecti...
CVE-2024-11929MEDIUM6.4The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp...
CVE-2024-11907MEDIUM6.4The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram...
CVE-2024-11815MEDIUM6.1The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
CVE-2024-11686MEDIUM6.1The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts...
CVE-2024-11642CRITICAL9.8The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Paginatio...
CVE-2024-11328MEDIUM6.1The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ...
CVE-2024-13153MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg...
CVE-2024-12802CRITICAL9.1SSL-VPN MFA Bypass in SonicWALL SSL-VPN can arise in specific cases due to the separate handling of UPN (User Principal ...
CVE-2024-43663CRITICAL9.8There are many buffer overflow vulnerabilities present in several CGI binaries of the charging station.This issue affect...
CVE-2024-43662MEDIUM5.3The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv...
CVE-2024-43661CRITICAL9.8The <redacted>.so library, which is used by <redacted>, is vulnerable to a buffer overflow in the code that handles the ...
CVE-2024-43660HIGH7.5The CGI script <redacted>.sh can be used to download any file on the filesystem. This issue affects Iocharger firmware ...
CVE-2024-43659HIGH8.3After gaining access to the firmware of a charging station, a file at <redacted> can be accessed to obtain default crede...
CVE-2024-43658HIGH7.2Patch traversal, External Control of File Name or Path vulnerability in Iocharger Home allows deletion of arbitrary fil...
CVE-2024-43657CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43656CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43655CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43654CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware...
CVE-2024-43653CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Inj...
CVE-2024-43652CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...
CVE-2024-43651CRITICAL9.3Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now