2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-40898HIGH7.5SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes t...
CVE-2024-40725MEDIUM5.3A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type b...
CVE-2024-5555MEDIUM6.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-5554MEDIUM6.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-3242HIGH8.8The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension vali...
CVE-2024-40764HIGH7.5Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Den...
CVE-2024-29014HIGH8.8Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an att...
CVE-2024-41011HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page w...
CVE-2024-6164CRITICAL9.8The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. T...
CVE-2024-6705MEDIUM5.5The RegLevel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,...
CVE-2024-6599MEDIUM4.3The Meks Video Importer plugin for WordPress is vulnerable to unauthorized API key modification due to a missing capabil...
CVE-2024-6175MEDIUM5.4The Booking Ultra Pro Appointments Booking Calendar Plugin plugin for WordPress is vulnerable to unauthorized modificati...
CVE-2024-5964MEDIUM6.4The Zenon Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme...
CVE-2024-5726HIGH8.8The Timeline Event History plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includi...
CVE-2024-41184CRITICAL9.8In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: ...
CVE-2024-39682MEDIUM5.4Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to HTML Injection in versions up ...
CVE-2024-39681HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-39680HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-39679HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin for WordPress is vulnerable to Cross-Site Request Forgery (CS...
CVE-2024-39678HIGH8.8Cooked is a recipe plugin for WordPress. The Cooked plugin is vulnerable to Cross-Site Request Forgery (CSRF) in version...
CVE-2024-40492HIGH7.1Cross Site Scripting vulnerability in Heartbeat Chat v.15.2.1 allows a remote attacker to execute arbitrary code via the...
CVE-2024-40402MEDIUM6.3A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulne...
CVE-2024-40119HIGH8.8Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (...
CVE-2024-39126MEDIUM5.4Roundup before 2.4.0 allows XSS via JavaScript in PDF, XML, and SVG documents.
CVE-2024-39125MEDIUM5.4Roundup before 2.4.0 allows XSS via a SCRIPT element in an HTTP Referer header.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now