2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9888MEDIUM5.4The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-9873MEDIUM5.4The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordP...
CVE-2024-10018CRITICAL9.8Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any une...
CVE-2024-9891MEDIUM4.3The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due...
CVE-2024-9652MEDIUM6.1The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all...
CVE-2024-9649MEDIUM4.3The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2024-9647MEDIUM6.1The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all version...
CVE-2024-9634CRITICAL9.8The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all ...
CVE-2024-9521MEDIUM6.4The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and i...
CVE-2024-9305CRITICAL9.8The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in...
CVE-2024-9105CRITICAL9.8The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This...
CVE-2024-9104MEDIUM5.6The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. ...
CVE-2024-8787MEDIUM6.1The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
CVE-2024-8541MEDIUM6.1The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin fo...
CVE-2024-49340HIGH8.8IBM Watson Studio Local 1.2.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malic...
CVE-2024-38204MEDIUM6.5Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
CVE-2024-38190HIGH8.6Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a netwo...
CVE-2024-38139HIGH8.8Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
CVE-2024-45085HIGH7.5IBM WebSphere Application Server 8.5 is vulnerable to a denial of service, under certain configurations, caused by an un...
CVE-2024-10004CRITICAL9.1Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in so...
CVE-2024-9966MEDIUM5.3Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass ...
CVE-2024-9965HIGH8.8Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker wh...
CVE-2024-9964MEDIUM4.3Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced...
CVE-2024-9963MEDIUM4.3Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convince...
CVE-2024-9962MEDIUM4.3Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now