2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10919CRITICAL9.8A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an...
CVE-2024-6861HIGH7.5A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is ena...
CVE-2024-35146MEDIUM5.4IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This ...
CVE-2024-10916MEDIUM5.3A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 202410...
CVE-2024-10082CRITICAL9CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2024-10081CRITICAL10CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. ...
CVE-2024-10915CRITICAL9.8A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critic...
CVE-2024-10914CRITICAL9.8A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as cri...
CVE-2024-10186MEDIUM5.4The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode i...
CVE-2024-8323MEDIUM5.4The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-10168MEDIUM5.4The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Store...
CVE-2024-10715MEDIUM5.4The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map b...
CVE-2024-9902MEDIUM6.3A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace...
CVE-2024-8615CRITICAL9.8The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-8614HIGH8.8The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-9681MEDIUM6.5When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it...
CVE-2024-52043MEDIUM5.3Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavatio...
CVE-2024-9946HIGH8.1The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authe...
CVE-2024-9307HIGH8.8The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up ...
CVE-2024-6626MEDIUM5.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized...
CVE-2024-10543MEDIUM4.3The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability...
CVE-2024-10535MEDIUM5.3The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-10020HIGH8.1The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, an...
CVE-2024-9934MEDIUM6.1The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back...
CVE-2024-7879MEDIUM4.8The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high pr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now