2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-56771MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02...
CVE-2024-51442HIGH8.8Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specia...
CVE-2024-56770MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: account for backlog updates from ...
CVE-2024-55459MEDIUM6.5An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar fi...
CVE-2024-13187MEDIUM5.3A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vul...
CVE-2024-55656HIGH8.8RedisBloom adds a set of probabilistic data structures to Redis. There is an integer overflow vulnerability in RedisBloo...
CVE-2024-55517HIGH8.8An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the...
CVE-2024-51737HIGH7RediSearch is a Redis module that provides querying, secondary indexing, and full-text search for Redis. An authenticate...
CVE-2024-51480HIGH7RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYIND...
CVE-2024-12337MEDIUM6.1The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘p...
CVE-2024-11830MEDIUM6.4The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline set...
CVE-2024-11423HIGH7.5The Ultimate Gift Cards for WooCommerce – Create WooCommerce Gift Cards, Gift Vouchers, Redeem & Manage Digital Gift Cou...
CVE-2024-12854HIGH8.8The Garden Gnome Package plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-12853HIGH8.8The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-12712MEDIUM5.3The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-9939HIGH7.5The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2...
CVE-2024-54676CRITICAL9.8Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0 Description: Def...
CVE-2024-45033HIGH8.1Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro...
CVE-2024-13186HIGH7.5The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-13185HIGH7.5The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2024-12855MEDIUM5.4The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on...
CVE-2024-12328MEDIUM6.4The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-11939HIGH7.5The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ para...
CVE-2024-11350CRITICAL9.8The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and i...
CVE-2024-13173HIGH7.5The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now