2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-3513MEDIUM5.4The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-38857MEDIUM6.1Improper neutralization of input in Checkmk before versions 2.3.0p8, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows attacker...
CVE-2024-37479HIGH8.8Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widge...
CVE-2024-37134MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h...
CVE-2024-37133MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h...
CVE-2024-37132MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high p...
CVE-2024-37126MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h...
CVE-2024-6172CRITICAL9.8The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-5219MEDIUM5.4The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feat...
CVE-2024-32854MEDIUM6.7Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local h...
CVE-2024-32853HIGH7.8Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A...
CVE-2024-32852HIGH7.5Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerab...
CVE-2024-0158MEDIUM6.7Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privilege...
CVE-2024-5767HIGH8.8The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2024-5606HIGH8.8The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_...
CVE-2024-4627MEDIUM5.4The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-3999MEDIUM4.8The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-1427MEDIUM5.4The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to ...
CVE-2024-5349HIGH8.8The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to...
CVE-2024-5419MEDIUM5.4The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-5938MEDIUM5.4The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the them...
CVE-2024-4679HIGH7.8Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNM...
CVE-2024-2819MEDIUM6.5Incorrect Default Permissions, Improper Preservation of Permissions vulnerability in Hitachi Ops Center Common Services ...
CVE-2024-39314MEDIUM4.7toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, t...
CVE-2024-39313MEDIUM5.3toy-blog is a headless content management system implementation. Starting in version 0.5.4 and prior to version 0.6.1, a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now