2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-8016HIGH7.2The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...
CVE-2024-42412MEDIUM6.1Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in...
CVE-2024-39300LOW3.7Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function...
CVE-2024-34577MEDIUM6.1Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to ...
CVE-2024-8333Rejected reason: Test CVE
CVE-2024-3673CRITICAL9.1The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), whic...
CVE-2024-5879MEDIUM5.4The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-3998MEDIUM5.4The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a...
CVE-2024-2694HIGH8.8The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via d...
CVE-2024-5784HIGH7.1The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing ...
CVE-2024-5061MEDIUM5.4The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wr...
CVE-2024-5024MEDIUM6.1The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr...
CVE-2024-4401MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_sli...
CVE-2024-8330HIGH8.86SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regula...
CVE-2024-8329HIGH8.86SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers wit...
CVE-2024-8328MEDIUM5.4Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific pa...
CVE-2024-8327HIGH8.8Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific p...
CVE-2024-45492CRITICAL9.8An issue was discovered in libexpat before 2.6.3. nextScaffoldPart in xmlparse.c can have an integer overflow for m_grou...
CVE-2024-45491CRITICAL9.8An issue was discovered in libexpat before 2.6.3. dtdCopy in xmlparse.c can have an integer overflow for nDefaultAtts on...
CVE-2024-45490HIGH7.5An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
CVE-2024-45488CRITICAL9.8One Identity Safeguard for Privileged Passwords before 7.5.2 allows unauthorized access because of an issue related to c...
CVE-2024-8234CRITICAL9.8** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the functions formSysCmd(), formUpgradeCert(), and ...
CVE-2024-2881HIGH8.8Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6...
CVE-2024-1545HIGH8.8Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on...
CVE-2024-1543MEDIUM5.5The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacke...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now