2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5640MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is ...
CVE-2024-5612MEDIUM5.4The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_l...
CVE-2024-5425MEDIUM5.4The WP jQuery Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ attribute in al...
CVE-2024-37384MEDIUM6.1Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via list columns from user preferences.
CVE-2024-37383MEDIUM6.1Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.
CVE-2024-36082MEDIUM6.5SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated ...
CVE-2024-1988MEDIUM5.4The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre...
CVE-2024-5607MEDIUM5.4The GDPR CCPA Compliance & Cookie Consent Banner plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-3987MEDIUM5.4The WP Mobile Menu – The Mobile-Friendly Responsive Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-1768MEDIUM5.4The Clever Fox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's info box block in all ...
CVE-2024-1689MEDIUM4.3The WooCommerce Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-4013MEDIUM5.6A bug exists in the API, mesh_node_power_off(), which fails to copy the contents of the Replay Protection List (RPL) fr...
CVE-2024-36775MEDIUM5.4A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HT...
CVE-2024-22525MEDIUM5.5dnspod-sr 0dfbd37 contains a SEGV.
CVE-2024-22524MEDIUM5.5dnspod-sr 0dfbd37 is vulnerable to buffer overflow.
CVE-2024-36795MEDIUM4Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories em...
CVE-2024-5550MEDIUM5.3In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system pa...
CVE-2024-5478MEDIUM6.1A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of luna...
CVE-2024-5278MEDIUM6.1gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of ...
CVE-2024-5248MEDIUM6.5In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in ...
CVE-2024-5206MEDIUM4.7A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to ...
CVE-2024-5131MEDIUM6.5An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and includi...
CVE-2024-5126MEDIUM6.5An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.pat...
CVE-2024-4890MEDIUM4.9A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' pr...
CVE-2024-3404MEDIUM6.5In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now