2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4741HIGH7.5Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously fre...
CVE-2024-8001MEDIUM4.3A vulnerability was found in VIWIS LMS 9.11. It has been classified as critical. Affected is an unknown function of the ...
CVE-2024-11028CRITICAL9.8The MultiManager WP – Manage All Your WordPress Sites Easily plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2024-9682MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-9668MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-9059MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Googl...
CVE-2024-10877MEDIUM6.1The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-52268MEDIUM4.8Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0. If this vulnerabi...
CVE-2024-9409HIGH7.5CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive re...
CVE-2024-8938CRITICAL9.2CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a...
CVE-2024-8937HIGH8.3CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a...
CVE-2024-8936HIGH8.3CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory a...
CVE-2024-8935HIGH7.7CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confide...
CVE-2024-21541CRITICAL9.8Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function ...
CVE-2024-21540Rejected reason: This issue is not a vulnerability because no real attack scenario can happen.
CVE-2024-11150CRITICAL9.8The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file p...
CVE-2024-10800HIGH8.8The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability c...
CVE-2024-10575CRITICAL9.8CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and...
CVE-2024-8933HIGH7.5CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-10828CRITICAL9.8The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up ...
CVE-2024-10820CRITICAL9.8The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid...
CVE-2024-10816HIGH7.5The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6....
CVE-2024-10802MEDIUM5.3The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2024-10794MEDIUM4.3The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versi...
CVE-2024-10174HIGH7.3The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now