2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12570MEDIUM6.7An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior ...
CVE-2024-12292MEDIUM4An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 pr...
CVE-2024-11274HIGH8.7An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 pr...
CVE-2024-10043LOW3.1An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting...
CVE-2024-4109Rejected reason: Red Hat Product Security has determined that this CVE is not a security vulnerability.
CVE-2024-21574CRITICAL10The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint us...
CVE-2024-12401MEDIUM4.4A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager...
CVE-2024-12397HIGH7.4A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming ...
CVE-2024-12333MEDIUM6.5The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8....
CVE-2024-12160MEDIUM6.1The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due ...
CVE-2024-11760MEDIUM6.4The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...
CVE-2024-12564MEDIUM6.9Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWE...
CVE-2024-12329MEDIUM4.3The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2024-12312HIGH8.1The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...
CVE-2024-12201MEDIUM4.3The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capa...
CVE-2024-11727MEDIUM4.4The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating...
CVE-2024-11724MEDIUM4.3The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plug...
CVE-2024-11181MEDIUM4.3The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all ver...
CVE-2024-10784MEDIUM5.4The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-10583MEDIUM5.4The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress...
CVE-2024-9881MEDIUM4.8The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-9641MEDIUM4.8The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which cou...
CVE-2024-9428MEDIUM4.8The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow hi...
CVE-2024-12265MEDIUM5.3The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due ...
CVE-2024-12263MEDIUM4.3The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now