2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8675MEDIUM4.3The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-8632MEDIUM6.5The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and mo...
CVE-2024-8548HIGH8.1The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-7869HIGH7.2The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and i...
CVE-2024-7434HIGH8.8The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via...
CVE-2024-7433HIGH8.8The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 vi...
CVE-2024-7432HIGH8.8The Unseen Blog theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 vi...
CVE-2024-8107MEDIUM5.4The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers...
CVE-2024-8421Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2024-21531MEDIUM5.3All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigat...
CVE-2024-21489HIGH8.2Versions of the package uplot before 1.6.31 are vulnerable to Prototype Pollution via the uplot.assign function due to m...
CVE-2024-0116MEDIUM6.5NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing ...
CVE-2024-47295HIGH8.1Insecure initial password configuration issue in SEIKO EPSON Web Config allows a remote unauthenticated attacker to set ...
CVE-2024-9360CRITICAL9.8A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been classified as critical. This a...
CVE-2024-8981HIGH7.1The Broken Link Checker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-9359CRITICAL9.8A vulnerability was found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by thi...
CVE-2024-9358MEDIUM5.9A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability ...
CVE-2024-47560HIGH7.8RevoWorks Cloud Client 3.0.91 and earlier contains an incorrect authorization vulnerability. If this vulnerability is ex...
CVE-2024-47396MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Ad...
CVE-2024-9194CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsof...
CVE-2024-45073MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p...
CVE-2024-7675HIGH7.8A maliciously crafted DWF file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Use-After-Free. A mali...
CVE-2024-7674HIGH7.8A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer O...
CVE-2024-7673HIGH7.8A maliciously crafted DWFX file, when parsed in w3dtk.dll through Autodesk Navisworks, can force a Heap-based Buffer Ove...
CVE-2024-7672HIGH7.8A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bou...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now