2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45781MEDIUM6.7A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string...
CVE-2024-45776MEDIUM6.7When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its ...
CVE-2024-45775MEDIUM5.2A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for...
CVE-2024-57056MEDIUM5.4Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to sys...
CVE-2024-57055MEDIUM5Server-Side Access Control Bypass vulnerability in WombatDialer before 25.02 could allow unauthorized users to potential...
CVE-2024-45774MEDIUM6.7A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bou...
CVE-2024-56882MEDIUM5.4Sage DPW before 2024_12_000 is vulnerable to Cross Site Scripting (XSS). Low-privileged Sage users with employee role pr...
CVE-2024-49589MEDIUM6.5Foundry Artifacts was found to be vulnerable to a Denial Of Service attack due to disk being potentially filled up based...
CVE-2024-39328MEDIUM6.8Insecure Permissions in Atos Eviden IDRA and IDCA before 2.7.0. A highly trusted role (Config Admin) could exceed their ...
CVE-2024-13689MEDIUM6.3The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...
CVE-2024-13783MEDIUM4.3The FormCraft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check in for...
CVE-2024-13691MEDIUM6.5The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_...
CVE-2024-13667MEDIUM5.4The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all v...
CVE-2024-13718MEDIUM4.3The Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later plugin for WordPress is vulnerable to Cross-...
CVE-2024-13395MEDIUM5.4The Threepress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'threepress' shortcode...
CVE-2024-13316MEDIUM5.3The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin...
CVE-2024-13795MEDIUM4.3The Ecwid by Lightspeed Ecommerce Shopping Cart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ...
CVE-2024-13704MEDIUM6.1The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'st_user_title' paramet...
CVE-2024-13575MEDIUM5.4The Web Stories Enhancer – Level Up Your Web Stories plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-13465MEDIUM5.4The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Tabl...
CVE-2024-11895MEDIUM5.4The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-11376MEDIUM6.1The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin...
CVE-2024-13523MEDIUM5.4The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1...
CVE-2024-45320MEDIUM6.5Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier...
CVE-2024-13438MEDIUM4.3The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now