2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9587MEDIUM4.3The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-9586MEDIUM5.3The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-9543MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-9538MEDIUM6.5The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2024-9507MEDIUM4.9The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-9436MEDIUM6.1The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner...
CVE-2024-9346MEDIUM6.1The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' pa...
CVE-2024-9234CRITICAL9.8The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerabl...
CVE-2024-9232MEDIUM6.1The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripti...
CVE-2024-9221MEDIUM6.1The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou...
CVE-2024-9211MEDIUM6.1The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-9164HIGH8.8An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prio...
CVE-2024-9051MEDIUM6.4The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-...
CVE-2024-8970HIGH8.8An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 pr...
CVE-2024-8913MEDIUM4.3The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-7514MEDIUM6.5The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient ...
CVE-2024-6971MEDIUM4.4A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.p...
CVE-2024-5005MEDIUM4.3An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 11.4 before 17.2.9, all ver...
CVE-2024-48987MEDIUM6.6Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the AP...
CVE-2024-45317HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allow...
CVE-2024-45316HIGH7.8The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12...
CVE-2024-45315MEDIUM5.5The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12...
CVE-2024-21534CRITICAL9.8All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitizati...
CVE-2024-9822CRITICAL9.8The Pedalo Connector plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.5...
CVE-2024-9818CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affect...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now