2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-31415HIGH8.1The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes su...
CVE-2024-31414MEDIUM6.1The Eaton Foreseer software provides users the capability to customize the dashboard in WebView pages. However, the inpu...
CVE-2024-6587HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows ...
CVE-2024-44798MEDIUM4.8phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-det...
CVE-2024-44685MEDIUM5Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information...
CVE-2024-42025HIGH7.8A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V...
CVE-2024-8747MEDIUM5.4The Email Obfuscate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'email-...
CVE-2024-8737MEDIUM6.1The PDF Thumbnail Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q...
CVE-2024-8734MEDIUM6.1The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...
CVE-2024-8732MEDIUM6.1The Roles & Capabilities plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_quer...
CVE-2024-8731MEDIUM6.1The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho...
CVE-2024-8730MEDIUM6.1The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg w...
CVE-2024-8714MEDIUM6.1The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scriptin...
CVE-2024-8269MEDIUM6.5The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user r...
CVE-2024-8242HIGH8.8The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uplo...
CVE-2024-7423HIGH8.8The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1....
CVE-2024-6544MEDIUM5.3The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, ...
CVE-2024-5884MEDIUM5.4The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in a...
CVE-2024-5870MEDIUM5.4The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's...
CVE-2024-5869MEDIUM5.4The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme...
CVE-2024-5867MEDIUM5.4The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme'...
CVE-2024-5789MEDIUM5.4The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the them...
CVE-2024-46713HIGH7.8In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reporte...
CVE-2024-46049CRITICAL9.8Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.
CVE-2024-46048CRITICAL9.8Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now