2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7146HIGH8.8The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includin...
CVE-2024-7136MEDIUM6.4The JetSearch plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions u...
CVE-2024-25008MEDIUM6.8Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Valida...
CVE-2024-7501MEDIUM4.2The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2024-6460CRITICAL9.8The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parame...
CVE-2024-7301MEDIUM6.1The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-7422MEDIUM4.3The Theme My Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-7630HIGH7.5The Relevanssi – A Better Search plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-7853HIGH8.8A vulnerability was found in SourceCodester Yoga Class Registration System up to 1.0. It has been classified as critical...
CVE-2024-7852MEDIUM5.4A vulnerability was found in SourceCodester Yoga Class Registration System 1.0 and classified as problematic. This issue...
CVE-2024-7851CRITICAL9.8A vulnerability has been found in SourceCodester Yoga Class Registration System 1.0 and classified as critical. This vul...
CVE-2024-7849HIGH8.8** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L...
CVE-2024-7845HIGH7.5A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0 and classified as critical. Affected by th...
CVE-2024-43378HIGH7.8calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who ins...
CVE-2024-43374MEDIUM4.7The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new fi...
CVE-2024-43370HIGH7.2gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dict...
CVE-2024-43369HIGH7.2Ibexa RichText Field Type is a Field Type for supporting rich formatted text stored in a structured XML format. In versi...
CVE-2024-7844MEDIUM5.4A vulnerability has been found in SourceCodester Online Graduate Tracer System 1.0 and classified as problematic. Affect...
CVE-2024-7843HIGH7.5A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Aff...
CVE-2024-7842HIGH7.5A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0...
CVE-2024-7841HIGH7.5A vulnerability classified as critical was found in SourceCodester Clinics Patient Management System 1.0. This vulnerabi...
CVE-2024-34743HIGH7.8In setTransactionState of SurfaceFlinger.cpp, there is a possible way to perform tapjacking due to a logic error in the ...
CVE-2024-34742MEDIUM5.5In shouldWrite of OwnersData.java, there is a possible edge case that prevents MDM policies from being persisted due to ...
CVE-2024-34741HIGH7.8In setForceHideNonSystemOverlayWindowIfNeeded of WindowState.java, there is a possible way for message content to be vis...
CVE-2024-34740HIGH7.8In attributeBytesBase64 and attributeBytesHex of BinaryXmlSerializer.java, there is a possible arbitrary XML injection d...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now