2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-1793HIGH7.2The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin fo...
CVE-2024-1772HIGH8.8The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object...
CVE-2024-1751HIGH8.8The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via ...
CVE-2024-1536HIGH7.4The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress...
CVE-2024-1505HIGH8.8The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege esc...
CVE-2024-1311HIGH8.8The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio...
CVE-2024-1203HIGH8.8The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress...
CVE-2024-0683HIGH7.5The Bulgarisation for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to missing capability ch...
CVE-2024-0368HIGH8.6The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to Sensitive Informatio...
CVE-2024-0161HIGH8.4Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulner...
CVE-2024-28684HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/module_...
CVE-2024-28675HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/diy_edit.php
CVE-2024-28665HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article...
CVE-2024-28432HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/article...
CVE-2024-28431HIGH8.8DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog...
CVE-2024-2415HIGH7.8Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allo...
CVE-2024-2414HIGH8.8The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the...
CVE-2024-26529HIGH7.5An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) vi...
CVE-2024-2400HIGH8.8Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially ...
CVE-2024-2107HIGH7.5The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2024-24092HIGH7.8SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via...
CVE-2024-23300HIGH7.8A use-after-free issue was addressed with improved memory management. This issue is fixed in GarageBand 10.4.11. Process...
CVE-2024-28186HIGH7.1FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free ...
CVE-2024-28121HIGH8.8stimulus_reflex is a system to extend the capabilities of both Rails and Stimulus by intercepting user interactions and ...
CVE-2024-27894HIGH8.8The Pulsar Functions Worker includes a capability that permits authenticated users to create functions where the functio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now