2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9696MEDIUM5.4The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' sh...
CVE-2024-9595MEDIUM5.4The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-8915MEDIUM6.4The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-8760MEDIUM5.3The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to,...
CVE-2024-9756MEDIUM4.3The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads ...
CVE-2024-9704MEDIUM5.4The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_so...
CVE-2024-9047CRITICAL9.8The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.2...
CVE-2024-9824MEDIUM4.3The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a...
CVE-2024-9778MEDIUM4.3The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2024-9776MEDIUM4.8The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in a...
CVE-2024-9670MEDIUM6.1The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wi...
CVE-2024-9656MEDIUM6.4The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers...
CVE-2024-9187MEDIUM4.3The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check ...
CVE-2024-7489MEDIUM4.4The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2024-9860MEDIUM5.4The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing...
CVE-2024-9821HIGH8.8The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missin...
CVE-2024-9592MEDIUM6.1The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and...
CVE-2024-45754HIGH7.2An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before...
CVE-2024-35522HIGH7.2Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injectio...
CVE-2024-35517HIGH7.2Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.
CVE-2024-48938HIGH7.5Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails...
CVE-2024-48937MEDIUM6.1Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows XSS. JavaScript code in the short description of t...
CVE-2024-48788HIGH7.5An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firm...
CVE-2024-48772CRITICAL9.1An issue in C-CHIP (com.cchip.cchipamaota) v.1.2.8 allows a remote attacker to obtain sensitive information via the firm...
CVE-2024-46468HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now