2024 CVE Vulnerabilities

39,239 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7418MEDIUM4.3The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to ...
CVE-2024-7132MEDIUM4.8The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of i...
CVE-2024-6927MEDIUM4.8The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-6551MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all ...
CVE-2024-5987MEDIUM4.3The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-5857MEDIUM5.3The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress...
CVE-2024-5624MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based a...
CVE-2024-5623HIGH7.8An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get ...
CVE-2024-5622HIGH7.8An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may...
CVE-2024-5417MEDIUM5.4The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting the...
CVE-2024-4428CRITICAL9.8Missing Authentication for Critical Function, Missing Authorization vulnerability in Menulux Information Technologies Ma...
CVE-2024-45440MEDIUM5.3core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash...
CVE-2024-43986MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople ...
CVE-2024-43700HIGH7.8xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data, resulting in a stack-ba...
CVE-2024-3944MEDIUM4.8The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and in...
CVE-2024-38304MEDIUM6.5Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of B...
CVE-2024-38303MEDIUM6Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability....
CVE-2024-29731CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29730CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29729CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29728CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29727CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29726CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29725CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...
CVE-2024-29724CRITICAL9.8SQL injection vulnerabilities in SportsNET affecting version 4.0.1. These vulnerabilities could allow an attacker to ret...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now