2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5614MEDIUM5.3The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-6569MEDIUM5.3The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and...
CVE-2024-6458MEDIUM6.4The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a m...
CVE-2024-5969MEDIUM5.3The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versi...
CVE-2024-42029MEDIUM6.3xdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e...
CVE-2024-6661MEDIUM4.4The ParityPress – Parity Pricing with Discount Rules plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-6634MEDIUM6.4The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconver...
CVE-2024-6591MEDIUM5.8The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due ...
CVE-2024-6573MEDIUM5.3The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0....
CVE-2024-6566MEDIUM5.3The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and in...
CVE-2024-6549MEDIUM5.3The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includin...
CVE-2024-6548MEDIUM5.3The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including...
CVE-2024-6547MEDIUM5.3The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1...
CVE-2024-6546MEDIUM5.3The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and inclu...
CVE-2024-6545MEDIUM5.3The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including...
CVE-2024-6431HIGH8.8The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-6152HIGH8.8The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5...
CVE-2024-4410MEDIUM5.4The IgnitionDeck Crowdfunding Platform plugin for WordPress is vulnerable to Missing Authorization in versions up to, an...
CVE-2024-1804MEDIUM4.3The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-1798MEDIUM5.3The Tutor LMS – Migration Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2024-40433HIGH8.8Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view...
CVE-2024-37034MEDIUM5.9An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are...
CVE-2024-41815HIGH7Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable ...
CVE-2024-41628HIGH7.5Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and ...
CVE-2024-41120CRITICAL9.8streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now