2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37933CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in anhvnit Woocommerc...
CVE-2024-37932HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in anhvnit Woocommerce Open...
CVE-2024-37928HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allo...
CVE-2024-37927CRITICAL9.8Incorrect Privilege Assignment vulnerability in NooTheme Jobmonster noo-jobmonster allows Privilege Escalation.This issu...
CVE-2024-37564HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlu...
CVE-2024-37560HIGH8Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects W...
CVE-2024-37544MEDIUM4.3Missing Authorization vulnerability in Saleswonder Team: Tobias Get Better Reviews for WooCommerce more-better-reviews-f...
CVE-2024-37213HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forger...
CVE-2024-37202MEDIUM6.5Missing Authorization vulnerability in BinaryCarpenter Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Bina...
CVE-2024-35773HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (X...
CVE-2024-6495MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Anim...
CVE-2024-5325MEDIUM6.5The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up...
CVE-2024-41006MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netrom: Fix a memory leak in nr_heartbeat_expiry() ...
CVE-2024-41005MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: netpoll: Fix race condition in netpoll_owner_active...
CVE-2024-41004MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing: Build event generation tests only as modul...
CVE-2024-41003HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reg_set_min_max corruption of fake_reg Ju...
CVE-2024-41002MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - Fix memory leak for sec res...
CVE-2024-41001MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: work around a potential audit memo...
CVE-2024-41000HIGH7.8In the Linux kernel, the following vulnerability has been resolved: block/ioctl: prefer different overflow check Runni...
CVE-2024-40999MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: ena: Add validation for completion descriptors...
CVE-2024-40998MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ext4: fix uninitialized ratelimit_state->lock acces...
CVE-2024-40997MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: cpufreq: amd-pstate: fix memory leak on CPU EPP exi...
CVE-2024-40996HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid splat in pskb_pull_reason syzkaller bui...
CVE-2024-40995MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: fix possible infinite loop in t...
CVE-2024-40994HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ptp: fix integer overflow in max_vclocks_store On ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now