2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-44383MEDIUM6.8WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
CVE-2024-8413MEDIUM6.1Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://g...
CVE-2024-7821Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8289CRITICAL9.8The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to privi...
CVE-2024-7870HIGH7.5The PixelYourSite – Your smart PIXEL (TAG) & API Manager and the PixelYourSite PRO plugins for WordPress are vulnerable ...
CVE-2024-45507CRITICAL9.8Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OF...
CVE-2024-45195HIGH7.5Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Us...
CVE-2024-8318MEDIUM5.4The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks...
CVE-2024-8123MEDIUM5.4The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference ...
CVE-2024-8121MEDIUM4.3The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user...
CVE-2024-8119MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-8117MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-8106MEDIUM6.5The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2024-8104MEDIUM6.5The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versio...
CVE-2024-8102HIGH8.8The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-8325MEDIUM5.4The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Count...
CVE-2024-7786MEDIUM5.3The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthentica...
CVE-2024-6926CRITICAL9.8The Viral Signup WordPress plugin through 2.1 does not properly sanitise and escape a parameter before using it in a SQ...
CVE-2024-6889MEDIUM4.8The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o...
CVE-2024-6888MEDIUM4.8The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o...
CVE-2024-6722MEDIUM4.8The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and e...
CVE-2024-6020MEDIUM6.1The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_...
CVE-2024-34661MEDIUM4.3Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to ...
CVE-2024-34660HIGH7.8Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary c...
CVE-2024-34659MEDIUM5.3Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now