2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12416HIGH7.5The Live Sales Notification for Woocommerce – Woomotiv plugin for WordPress is vulnerable to SQL Injection via the 'woom...
CVE-2024-12402CRITICAL9.8The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is vulnerable to privilege e...
CVE-2024-12098MEDIUM6.1The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword'...
CVE-2024-12022——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-52485. Reason: This candidate is a ...
CVE-2024-11934MEDIUM6.4The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-11899MEDIUM6.4The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short...
CVE-2024-11777MEDIUM6.4The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for...
CVE-2024-11437MEDIUM4.9The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a...
CVE-2024-55553HIGH7.5In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via ...
CVE-2024-54767HIGH7.5An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sen...
CVE-2024-54764MEDIUM6.5An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit...
CVE-2024-54763MEDIUM6.5An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti...
CVE-2024-53936MEDIUM6.3The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any applicati...
CVE-2024-53935MEDIUM6.5The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables ...
CVE-2024-53934HIGH7.7The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2...
CVE-2024-53933MEDIUM6.3The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Andr...
CVE-2024-53932CRITICAL9.1The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1....
CVE-2024-53931CRITICAL9.1The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any appli...
CVE-2024-51741MEDIUM4.4Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat...
CVE-2024-48457HIGH7.5An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ...
CVE-2024-48456HIGH7.5An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ...
CVE-2024-48455LOW2.7An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi ...
CVE-2024-46981CRITICAL9.8Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua...
CVE-2024-55076HIGH8.1Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.
CVE-2024-55075MEDIUM5.3Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now