2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9685MEDIUM4.3The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c...
CVE-2024-9581HIGH7.3The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i...
CVE-2024-9522HIGH8.8The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2....
CVE-2024-9519HIGH7.2The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check...
CVE-2024-9518CRITICAL9.8The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to ins...
CVE-2024-9457MEDIUM5.4The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up...
CVE-2024-9377MEDIUM6.1The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-9205MEDIUM6.1The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-9072MEDIUM5.4The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-9066MEDIUM5.4The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ...
CVE-2024-9065MEDIUM5.3The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-9064MEDIUM5.4The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v...
CVE-2024-9057MEDIUM5.4The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-8987MEDIUM5.4The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-8729MEDIUM6.1The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add...
CVE-2024-8513MEDIUM5.3The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable...
CVE-2024-7048MEDIUM5.4In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/...
CVE-2024-48958HIGH7.8execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c...
CVE-2024-48957HIGH7.8execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a c...
CVE-2024-48949CRITICAL9.1The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(s...
CVE-2024-48942MEDIUM5.9The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to eas...
CVE-2024-48941MEDIUM5.4The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp...
CVE-2024-8264MEDIUM5.5Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent...
CVE-2024-48933MEDIUM6.1A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary we...
CVE-2024-7041MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now