2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52812MEDIUM5.4LF Edge eKuiper is an internet-of-things data analytics and stream processing engine. Prior to version 2.0.8, auser with...
CVE-2024-52905LOW2.7IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitiv...
CVE-2024-47109MEDIUM5.3IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 UI could disclosure the installation path ...
CVE-2024-12604MEDIUM6.5Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Pa...
CVE-2024-57492MEDIUM5.5An issue in redoxOS relibc before commit 98aa4ea5 allows a local attacker to cause a denial of service via the round_up_...
CVE-2024-13919MEDIUM6.1The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an im...
CVE-2024-13918MEDIUM6.1The Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an im...
CVE-2024-11638HIGH8.8The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog...
CVE-2024-43107HIGH7.2Improper Certificate Validation (CWE-295) in the Gallagher Milestone Integration Plugin (MIP) permits unauthenticated me...
CVE-2024-41724HIGH8.7Improper Certificate Validation (CWE-295) in the Gallagher Command Centre SALTO integration allowed an attacker to spoof...
CVE-2024-13924CRITICAL9.1The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions...
CVE-2024-10326MEDIUM4.3The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-13675MEDIUM5.4The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-13649MEDIUM5.4The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-11640HIGH8.8The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-13359CRITICAL9.8The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficien...
CVE-2024-13882HIGH8.8The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-13816MEDIUM5.4The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is...
CVE-2024-10321MEDIUM4.3The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13908HIGH7.2The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2024-11087CRITICAL9.8The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerab...
CVE-2024-13844MEDIUM4.9The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up...
CVE-2024-13826MEDIUM5.4The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could al...
CVE-2024-13825MEDIUM6.1The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-12119MEDIUM5.4The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerabl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now