2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6553MEDIUM5.3The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all version...
CVE-2024-6836MEDIUM4.3The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ...
CVE-2024-6094MEDIUM4.8The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-40767MEDIUM6.5In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actuall...
CVE-2024-5861MEDIUM6.5The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a mi...
CVE-2024-3246MEDIUM5.4The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-7027HIGH7.3The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and includ...
CVE-2024-6756HIGH8.8The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2024-6755MEDIUM5.3The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing...
CVE-2024-6754MEDIUM4.3The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c...
CVE-2024-6753MEDIUM6.1The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in...
CVE-2024-6752MEDIUM5.4The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in ...
CVE-2024-6751MEDIUM6.5The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2024-6750HIGH7.5The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ...
CVE-2024-41656MEDIUM5.4Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1,...
CVE-2024-38176HIGH8.1An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate pri...
CVE-2024-38164HIGH8.8An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a ne...
CVE-2024-0981HIGH7.1Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. T...
CVE-2024-41668HIGH8.3The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data se...
CVE-2024-41665MEDIUM5.4Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnera...
CVE-2024-41661Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-50094. Reason: This candidate is a ...
CVE-2024-41664MEDIUM5.4Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a ...
CVE-2024-41178HIGH7.5Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and e...
CVE-2024-6714HIGH7.8An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate th...
CVE-2024-41663LOW3.5Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now