2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10939MEDIUM4.8The Image Widget WordPress plugin before 4.4.11 does not sanitise and escape some of its Image Widget settings, which co...
CVE-2024-10678MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.2.4 does not validate and escape some of its block options before outputt...
CVE-2024-21544HIGH8.6Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL ...
CVE-2024-21543HIGH7.1Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fai...
CVE-2024-12579MEDIUM5.3The Minify HTML plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to...
CVE-2024-12574MEDIUM5.4The SVG Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-11809MEDIUM6.1The Primer MyData for Woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'img_src'...
CVE-2024-11767MEDIUM6.4The NewsmanApp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'newsman_subscribe_wid...
CVE-2024-12572MEDIUM6.1The Hello In All Languages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-12300LOW3.7The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing ca...
CVE-2024-12603CRITICAL9.8A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application passwo...
CVE-2024-9508HIGH8.5Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose informat...
CVE-2024-12212HIGH8.5The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supp...
CVE-2024-12289MEDIUM5.9Boundary Community Edition and Boundary Enterprise (“Boundary”) incorrectly handle HTTP requests during the initializati...
CVE-2024-55888HIGH7.1Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the p...
CVE-2024-55886MEDIUM6.9OpenSearch Data Prepper is a component of the OpenSearch project that accepts, filters, transforms, enriches, and routes...
CVE-2024-55885HIGH7.5beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a has...
CVE-2024-55879HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with ...
CVE-2024-55878MEDIUM6.8SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in version 1.0.12 and prior to ve...
CVE-2024-55877HIGH8.8XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5...
CVE-2024-55876MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0,...
CVE-2024-55875CRITICAL9.8http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML Ex...
CVE-2024-55663CRITICAL9.8XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc...
CVE-2024-54811CRITICAL9.8A SQL injection vulnerability in /index.php in PHPGurukul Park Ticketing Management System v1.0 allows an attacker to ex...
CVE-2024-49147CRITICAL9.8Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now