2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34782HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34781HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-34780HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32847HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32844HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32841HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-32839HIGH7.2SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allow...
CVE-2024-29211MEDIUM4.7A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify se...
CVE-2024-10887MEDIUM6.4The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (ni...
CVE-2024-10854MEDIUM4.3The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-10853MEDIUM4.3The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-10852MEDIUM4.3The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil...
CVE-2024-10851MEDIUM6.1The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-10850MEDIUM6.1The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-10778MEDIUM4.3The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all ve...
CVE-2024-10717MEDIUM6.5The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a de...
CVE-2024-10686Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-51689. Reason: This candidate is a ...
CVE-2024-10629HIGH8.8The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file ...
CVE-2024-10577MEDIUM6.1The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected ...
CVE-2024-10038MEDIUM6.1The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to...
CVE-2024-28731MEDIUM4.3Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.3...
CVE-2024-28730MEDIUM5.4Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME al...
CVE-2024-28729CRITICAL9.8An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e...
CVE-2024-28728MEDIUM6.6Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME al...
CVE-2024-28726HIGH8An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to e...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now