2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-7548MEDIUM6.5The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' par...
CVE-2024-7150HIGH8.8The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id...
CVE-2024-6884MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its bloc...
CVE-2024-6824MEDIUM4.3The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to...
CVE-2024-6481MEDIUM4.8The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could al...
CVE-2024-5226MEDIUM5.4The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload f...
CVE-2024-6987MEDIUM4.3The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec...
CVE-2024-6869HIGH7.1The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-5668MEDIUM5.4The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site S...
CVE-2024-6552MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in ...
CVE-2024-6254MEDIUM6.1The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-7492HIGH8.8The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-7350CRITICAL9.8The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable t...
CVE-2024-7561HIGH8.8The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via d...
CVE-2024-7560HIGH7.2The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via...
CVE-2024-7486HIGH8.8The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 v...
CVE-2024-38202HIGH7.3Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabli...
CVE-2024-21302MEDIUM6.7Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance f...
CVE-2024-6893HIGH7.5The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This all...
CVE-2024-6892MEDIUM6.1Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx w...
CVE-2024-6891HIGH8.8Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login ...
CVE-2024-6890HIGH8.8Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journ...
CVE-2024-6707HIGH8.8Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traver...
CVE-2024-6706MEDIUM6.1Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the contex...
CVE-2024-41912CRITICAL9.8A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now