2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7481HIGH8.8Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe ...
CVE-2024-7479HIGH8.8Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe comp...
CVE-2024-45817HIGH7.3In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status regis...
CVE-2024-31146HIGH7.5When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system ...
CVE-2024-31145HIGH7.5Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reportin...
CVE-2024-9169MEDIUM4.8The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v...
CVE-2024-8175HIGH7.5An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
CVE-2024-47303MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ...
CVE-2024-40761MEDIUM5.3Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using ...
CVE-2024-23454MEDIUM6.2Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be pres...
CVE-2024-8910MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2024-8678MEDIUM5.3The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-8290HIGH8.8The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is...
CVE-2024-3866MEDIUM6.1The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re...
CVE-2024-8658MEDIUM5.3The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo...
CVE-2024-7892MEDIUM4.3The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which cou...
CVE-2024-7878MEDIUM4.8The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-6845MEDIUM5.3The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, a...
CVE-2024-8668MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-8275CRITICAL9.8The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_...
CVE-2024-8516MEDIUM4.3The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an...
CVE-2024-8515MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget...
CVE-2024-8514HIGH7.2The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up...
CVE-2024-7385HIGH7.2The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all vers...
CVE-2024-9073MEDIUM5.4The GutenGeek Free Gutenberg Blocks for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now