2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8623HIGH7.3The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in al...
CVE-2024-8795HIGH8.8The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-8738MEDIUM6.1The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-8716MEDIUM6.1The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-8662MEDIUM6.1The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8657MEDIUM5.4The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc...
CVE-2024-8544MEDIUM6.1The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-8432MEDIUM4.3The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif...
CVE-2024-38269MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel ...
CVE-2024-38268MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG882...
CVE-2024-38267MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG88...
CVE-2024-38266MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG...
CVE-2024-7024CRITICAL9.6Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perf...
CVE-2024-7023HIGH8.8Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform priv...
CVE-2024-7022MEDIUM4.3Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor...
CVE-2024-7020MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI...
CVE-2024-7019MEDIUM4.3Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use...
CVE-2024-7018HIGH7.8Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit hea...
CVE-2024-8770MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server...
CVE-2024-8263LOW2.7An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PA...
CVE-2024-42861HIGH7.5An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted...
CVE-2024-47222CRITICAL9.8New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from exte...
CVE-2024-46639HIGH7.6A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML...
CVE-2024-44540MEDIUM6.6Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s...
CVE-2024-43201MEDIUM5.9The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now