2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11179MEDIUM6.5The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2024-10891MEDIUM6.4The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's...
CVE-2024-10665MEDIUM5.4The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data d...
CVE-2024-11176MEDIUM5.3Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access o...
CVE-2024-10127CRITICAL9.8Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLD...
CVE-2024-10126MEDIUM4.3Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7...
CVE-2024-52033MEDIUM5.3Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware ver...
CVE-2024-48895HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo...
CVE-2024-47865MEDIUM5.3Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earli...
CVE-2024-9239MEDIUM6.1The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q...
CVE-2024-8726MEDIUM6.1The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ...
CVE-2024-11277MEDIUM6.1The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, an...
CVE-2024-10900HIGH8.1The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-10899HIGH7.3The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versio...
CVE-2024-10855HIGH8.1The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that...
CVE-2024-10365MEDIUM4.3The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-9653MEDIUM6.1The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Sit...
CVE-2024-52614MEDIUM4Use of hard-coded cryptographic key issue exists in "Kura Sushi Official App Produced by EPARK" for Android versions pri...
CVE-2024-10515LOW3.5In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that...
CVE-2024-11278MEDIUM6.1The GD bbPress Attachments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-44309MEDIUM6.3A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2...
CVE-2024-44308HIGH8.8The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18...
CVE-2024-44307HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma...
CVE-2024-44306HIGH7.8A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app ma...
CVE-2024-52595MEDIUM6.1lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, th...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now