2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11143MEDIUM4.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up ...
CVE-2024-10882MEDIUM6.1The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-10684MEDIUM6.1The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' p...
CVE-2024-10593MEDIUM4.3The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2024-10531MEDIUM4.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-10530MEDIUM4.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-10529MEDIUM5.3The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-9614MEDIUM6.1The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-9578MEDIUM5.3The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked t...
CVE-2024-9426MEDIUM6.4The Aqua SVG Sprite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-8985MEDIUM6.4The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-8874MEDIUM6.1The AJAX Login and Registration modal popup + inline form plugin for WordPress is vulnerable to Reflected Cross-Site Scr...
CVE-2024-39712CRITICAL9.1Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version...
CVE-2024-39711CRITICAL9.1Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version...
CVE-2024-39710CRITICAL9.1Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version...
CVE-2024-39709HIGH7.8Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Se...
CVE-2024-38656CRITICAL9.1Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-38655HIGH7.2Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version...
CVE-2024-38654MEDIUM4.4Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with...
CVE-2024-38649HIGH7.5An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remot...
CVE-2024-37400HIGH7.5An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigg...
CVE-2024-37398HIGH7.8Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate t...
CVE-2024-37376HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34787HIGH7.8Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allo...
CVE-2024-34784HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now