2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11442MEDIUM6.4The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11433MEDIUM6.4The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11430MEDIUM6.5The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' short...
CVE-2024-11427MEDIUM6.4The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortco...
CVE-2024-11419MEDIUM6.1The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-11417MEDIUM6.1The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2024-11413MEDIUM6.4The HostFact bestelformulier integratie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-11279MEDIUM6.1The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-11015CRITICAL9.8The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including...
CVE-2024-10111HIGH8.1The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all version...
CVE-2024-55660CRITICAL9.8SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint...
CVE-2024-55659MEDIUM5.4SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is...
CVE-2024-55658HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint...
CVE-2024-55657HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists i...
CVE-2024-55652MEDIUM6.5PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an atta...
CVE-2024-54534CRITICAL9.8The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPa...
CVE-2024-54531MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to ...
CVE-2024-54529HIGH7.8A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS ...
CVE-2024-54528HIGH7.1A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, ...
CVE-2024-54527MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macO...
CVE-2024-54526MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS...
CVE-2024-54524MEDIUM5.5A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may ...
CVE-2024-54515HIGH7.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may b...
CVE-2024-54514HIGH8.6The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS...
CVE-2024-54513MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS S...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now