2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6579MEDIUM4.3The Web and WooCommerce Addons for WPBakery Builder plugin for WordPress is vulnerable to unauthorized plugin settings m...
CVE-2024-39887CRITICAL9.8An SQL Injection vulnerability in Apache Superset exists due to improper neutralization of special elements used in SQL ...
CVE-2024-6570MEDIUM5.3The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. Th...
CVE-2024-6565MEDIUM5.3The AForms — Form Builder for Price Calculator & Cost Estimation plugin for WordPress is vulnerable to Full Path Disclos...
CVE-2024-5852MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including...
CVE-2024-3779MEDIUM5.5Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker t...
CVE-2024-3587MEDIUM5.4The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-2691MEDIUM5.4The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable ...
CVE-2024-1937MEDIUM6.5The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-41008MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This pat...
CVE-2024-6559MEDIUM5.3The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path ...
CVE-2024-4780MEDIUM6.4The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eih...
CVE-2024-6557MEDIUM5.3The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Pos...
CVE-2024-6780LOW3.3Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security...
CVE-2024-40524CRITICAL9.8Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the web...
CVE-2024-4143CRITICAL9.8A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbit...
CVE-2024-40632LOW3.7Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the applica...
CVE-2024-4224MEDIUM5.4An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V...
CVE-2024-40630MEDIUM4.3OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2024-40627MEDIUM5.8Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by ...
CVE-2024-40624CRITICAL9.8TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes...
CVE-2024-39919LOW3.1@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an...
CVE-2024-39918MEDIUM4.3@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots an...
CVE-2024-39915CRITICAL9.9Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This au...
CVE-2024-39912MEDIUM5.3web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now