2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-4097HIGH7.2The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SVG upload feature...
CVE-2024-4033HIGH8.8The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2024-3957HIGH7.3The Booster for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and...
CVE-2024-3895HIGH8.8The WP Datepicker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-3849HIGH8.8The Click to Chat – HoliThemes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and inc...
CVE-2024-3717HIGH7.5The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Expo...
CVE-2024-3715HIGH7.2The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-3500HIGH8.8The ElementsKit Pro plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6...
CVE-2024-3499HIGH8.8The ElementsKit Elementor addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i...
CVE-2024-3047HIGH7.2The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in ve...
CVE-2024-2831HIGH8.8The Calendar plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcodes in all versions up to, and ...
CVE-2024-2661HIGH8.8The Barcode Scanner and Inventory manager. POS (Point of Sale) – scan barcodes & create orders with barcode reader. plug...
CVE-2024-2417HIGH8.8The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...
CVE-2024-25290HIGH8An issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter ...
CVE-2024-1945HIGH7.1The Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder plugin for WordPress is vulnerable to...
CVE-2024-1897HIGH7.5The Grid Gallery – Photo Image Grid Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions u...
CVE-2024-1896HIGH7.5The Photo Gallery – Responsive Photo Gallery, Image Gallery, Portfolio Gallery, Logo Gallery And Team Gallery plugin for...
CVE-2024-1797HIGH8.8The WP ULike – Most Advanced WordPress Marketing Toolkit plugin for WordPress is vulnerable to SQL Injection via the 'st...
CVE-2024-1677HIGH8.8The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is ...
CVE-2024-1173HIGH7.2The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is...
CVE-2024-33530HIGH7.5In Jitsi Meet before 9391, a logic flaw in password-protected Jitsi meetings (that make use of a lobby) leads to the dis...
CVE-2024-31964HIGH7.5A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-29309HIGH7.7An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Ser...
CVE-2024-3544HIGH7.5 Unauthenticated attackers can perform actions, using SSH private keys, by knowing the IP address and having access to t...
CVE-2024-3543HIGH7.5 Use of reversible password encryption algorithm allows attackers to decrypt passwords.  Sensitive information can be ea...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now