2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-7548 | MEDIUM | 6.5 | 0.6% | Aug 8, 2024 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' par... |
| CVE-2024-7150 | HIGH | 8.8 | 0.6% | Aug 8, 2024 | The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id... |
| CVE-2024-6884 | MEDIUM | 5.4 | 0.4% | Aug 8, 2024 | The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its bloc... |
| CVE-2024-6824 | MEDIUM | 4.3 | 0.4% | Aug 8, 2024 | The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to... |
| CVE-2024-6481 | MEDIUM | 4.8 | 0.3% | Aug 8, 2024 | The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could al... |
| CVE-2024-5226 | MEDIUM | 5.4 | 0.3% | Aug 8, 2024 | The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload f... |
| CVE-2024-6987 | MEDIUM | 4.3 | 0.3% | Aug 8, 2024 | The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec... |
| CVE-2024-6869 | HIGH | 7.1 | 0.3% | Aug 8, 2024 | The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-5668 | MEDIUM | 5.4 | 0.3% | Aug 8, 2024 | The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site S... |
| CVE-2024-6552 | MEDIUM | 5.3 | 0.4% | Aug 8, 2024 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in ... |
| CVE-2024-6254 | MEDIUM | 6.1 | 0.3% | Aug 8, 2024 | The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2024-7492 | HIGH | 8.8 | 0.3% | Aug 8, 2024 | The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2024-7350 | CRITICAL | 9.8 | 0.7% | Aug 8, 2024 | The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable t... |
| CVE-2024-7561 | HIGH | 8.8 | 0.7% | Aug 8, 2024 | The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d... |
| CVE-2024-7560 | HIGH | 7.2 | 0.6% | Aug 8, 2024 | The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via... |
| CVE-2024-7486 | HIGH | 8.8 | 0.6% | Aug 8, 2024 | The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 v... |
| CVE-2024-38202 | HIGH | 7.3 | 1.7% | Aug 8, 2024 | Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli... |
| CVE-2024-21302 | MEDIUM | 6.7 | 1.6% | Aug 8, 2024 | Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance f... |
| CVE-2024-6893 | HIGH | 7.5 | 32.9% | Aug 8, 2024 | The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This all... |
| CVE-2024-6892 | MEDIUM | 6.1 | 0.7% | Aug 8, 2024 | Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx w... |
| CVE-2024-6891 | HIGH | 8.8 | 1.0% | Aug 8, 2024 | Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login ... |
| CVE-2024-6890 | HIGH | 8.8 | 0.7% | Aug 7, 2024 | Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ... |
| CVE-2024-6707 | HIGH | 8.8 | 1.0% | Aug 7, 2024 | Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver... |
| CVE-2024-6706 | MEDIUM | 6.1 | 0.6% | Aug 7, 2024 | Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the contex... |
| CVE-2024-41912 | CRITICAL | 9.8 | 0.5% | Aug 7, 2024 | A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now