2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9351MEDIUM4.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site...
CVE-2024-5429HIGH7.6The Logo Slider WordPress plugin before 4.1.0 does not validate and escape some of its Slider Settings before outputtin...
CVE-2024-9347MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-9263CRITICAL9.8The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable...
CVE-2024-8719MEDIUM6.1The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like...
CVE-2024-7417MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t...
CVE-2024-49593MEDIUM5.3In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the ...
CVE-2024-9940MEDIUM4.3The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5....
CVE-2024-9863CRITICAL9.8The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up ...
CVE-2024-9862CRITICAL9.8The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in ve...
CVE-2024-9861HIGH8.1The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up...
CVE-2024-9240MEDIUM6.1The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-9215HIGH8.8The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu...
CVE-2024-45767MEDIUM6.5Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used...
CVE-2024-45766HIGH8.8Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code In...
CVE-2024-7994HIGH7.8A maliciously crafted RFA file, when parsed through Autodesk Revit, can force a Stack-Based Buffer Overflow. A malicious...
CVE-2024-7993HIGH7.8A maliciously crafted PDF file, when parsed through Autodesk Revit, may force an Out-of-Bounds Write vulnerability. A ma...
CVE-2024-48918HIGH8.1RDS Light is a simplified version of the Reflective Dialogue System (RDS), a self-reflecting AI framework. Versions prio...
CVE-2024-48758MEDIUM6.1dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the compone...
CVE-2024-48180CRITICAL9.8ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uplo...
CVE-2024-47889MEDIUM6.6Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9...
CVE-2024-47888MEDIUM6.6Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0....
CVE-2024-46213HIGH7.2REDAXO CMS v2.11.0 was discovered to contain a remote code execution (RCE) vulnerability.
CVE-2024-46212MEDIUM4.9An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory tr...
CVE-2024-44762MEDIUM5.3A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now