2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11585HIGH7.5The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing ...
CVE-2024-11201MEDIUM6.4The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo...
CVE-2024-10578HIGH8.8The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability ...
CVE-2024-10551MEDIUM4.8The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could al...
CVE-2024-10480MEDIUM4.3The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could a...
CVE-2024-11379MEDIUM6.1The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v...
CVE-2024-9769MEDIUM4.8The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-10836MEDIUM6.1The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions u...
CVE-2024-10247MEDIUM4.9The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection...
CVE-2024-49041MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-11149MEDIUM5.5In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
CVE-2024-6219LOW3.8Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust...
CVE-2024-6156LOW3.8Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was prese...
CVE-2024-52798HIGH7.7path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular exp...
CVE-2024-38920CRITICAL9.1Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via...
CVE-2024-38910HIGH7.5Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in th...
CVE-2024-37863CRITICAL9.8Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi...
CVE-2024-37862HIGH7.3Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-hum...
CVE-2024-37861CRITICAL9.8Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow vi...
CVE-2024-37860HIGH7.3Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allo...
CVE-2024-30964HIGH7.8Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig...
CVE-2024-30963HIGH7.8Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation...
CVE-2024-30962HIGH7.8Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation...
CVE-2024-30961HIGH7.8Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navig...
CVE-2024-54140LOW2.1sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient ver...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now