2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-51510MEDIUM5.5Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect s...
CVE-2024-10711HIGH8.8The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-10114HIGH8.1The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and in...
CVE-2024-47797HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-47404HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-47402MEDIUM5.5in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.
CVE-2024-47137HIGH7.8in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sens...
CVE-2024-10097HIGH8.1The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to...
CVE-2024-9883MEDIUM4.8The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-9689MEDIUM4.3The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow at...
CVE-2024-9459HIGH8.8Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in re...
CVE-2024-7877MEDIUM4.8The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not...
CVE-2024-7876MEDIUM4.8The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not...
CVE-2024-5578MEDIUM4.8The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could ...
CVE-2024-10810HIGH7.5A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an ...
CVE-2024-10809HIGH7.5A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some ...
CVE-2024-10808HIGH7.5A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability ...
CVE-2024-10807MEDIUM4.8A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue aff...
CVE-2024-10340MEDIUM6.4The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' short...
CVE-2024-10806MEDIUM4.8A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulner...
CVE-2024-51498MEDIUM6cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascri...
CVE-2024-50346MEDIUM5.1WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFee...
CVE-2024-32870MEDIUM5.8Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and ...
CVE-2024-31998HIGH8.8Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This i...
CVE-2024-31448MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-sit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now