2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51737HIGH7RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticate...
CVE-2024-51480HIGH7RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYIND...
CVE-2024-12337MEDIUM6.1The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘p...
CVE-2024-11830MEDIUM6.4The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline set...
CVE-2024-11423HIGH7.5The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Cou...
CVE-2024-12854HIGH8.8The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-12853HIGH8.8The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-12712MEDIUM5.3The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-9939HIGH7.5The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2...
CVE-2024-54676CRITICAL9.8Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Def...
CVE-2024-45033HIGH8.1Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro...
CVE-2024-13186HIGH7.5The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-13185HIGH7.5The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-12855MEDIUM5.4The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-12328MEDIUM6.4The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-11939HIGH7.5The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ para...
CVE-2024-11350CRITICAL9.8The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i...
CVE-2024-13173HIGH7.5The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-12045MEDIUM4.8The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored ...
CVE-2024-11635CRITICAL9.8The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi...
CVE-2024-9673Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-22333. Reason: This candidate is a ...
CVE-2024-8002MEDIUM6.9A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unk...
CVE-2024-12852MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' p...
CVE-2024-12851MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for...
CVE-2024-12584MEDIUM6.5The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now