2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12195MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-12221MEDIUM6.1The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonc...
CVE-2024-12583CRITICAL9.9The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all ...
CVE-2024-11930MEDIUM5.4The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2024-12701MEDIUM6.1The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-12545MEDIUM5.4The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin...
CVE-2024-12047MEDIUM6.1The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11974MEDIUM6.1The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_t...
CVE-2024-10932HIGH8.8The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1....
CVE-2024-55897MEDIUM4.3IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookie...
CVE-2024-55896MEDIUM5.4IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames.  This vuln...
CVE-2024-12237MEDIUM4.3The Photo Gallery Slideshow & Masonry Tiled Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in...
CVE-2024-11733HIGH7.3The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t...
CVE-2024-13129HIGH8.8A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th...
CVE-2024-56332MEDIUM5.3Next.js is a React framework for building full-stack web applications. Starting in version 13.0.0 and prior to versions ...
CVE-2024-56412MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56411MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56410MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-36613MEDIUM6.2FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potent...
CVE-2024-35365HIGH8.8FFmpeg version n6.1.1 has a double-free vulnerability in the fftools/ffmpeg_mux_init.c component of FFmpeg, specifically...
CVE-2024-56514MEDIUM5.3Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ...
CVE-2024-56513HIGH8.7Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes ...
CVE-2024-56409MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56366MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....
CVE-2024-56365MEDIUM5.4PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. Versions prior to 3.7.0, 2.3.5, 2.1.6, and 1....

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now