2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-54154CRITICAL9.8In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
CVE-2024-54153MEDIUM6.5In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query par...
CVE-2024-52278Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-52269HIGH8.2User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The Saa...
CVE-2024-11854MEDIUM6.4The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stor...
CVE-2024-10576CRITICAL9.4Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast rece...
CVE-2024-52277HIGH8.2User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displaye...
CVE-2024-52276HIGH8.2User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Disp...
CVE-2024-52275CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows ...
CVE-2024-52274CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_che...
CVE-2024-52273CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_ch...
CVE-2024-52272CRITICAL9.8Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanM...
CVE-2024-12107HIGH7.5Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause...
CVE-2024-11814MEDIUM6.1The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-5020MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip...
CVE-2024-11952HIGH7.5The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all...
CVE-2024-11880MEDIUM6.4The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-10787MEDIUM4.3The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to...
CVE-2024-10567HIGH7.5The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-11903MEDIUM6.4The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al...
CVE-2024-11769MEDIUM6.4The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f...
CVE-2024-11466MEDIUM6.1The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't...
CVE-2024-11293HIGH8.1The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & ...
CVE-2024-10664MEDIUM4.3The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modif...
CVE-2024-45717MEDIUM4.8The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now