2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-5424MEDIUM6.4The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2024-30135HIGH7.5HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot ...
CVE-2024-6288MEDIUM4.7The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress...
CVE-2024-5796MEDIUM6.4The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all ver...
CVE-2024-5788MEDIUM6.4The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's...
CVE-2024-39350HIGH7.5A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-m...
CVE-2024-39348HIGH7.5Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before...
CVE-2024-39347MEDIUM5.9Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227...
CVE-2024-30111HIGH7.5HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app ca...
CVE-2024-30110CRITICAL9.8HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A maliciou...
CVE-2024-2795MEDIUM5.3The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2...
CVE-2024-5730MEDIUM6.1The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-5729MEDIUM6.1The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back ...
CVE-2024-5728MEDIUM5.4The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-5727MEDIUM4.7The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-5570MEDIUM6.5The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which c...
CVE-2024-39352MEDIUM4.9A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote aut...
CVE-2024-39351HIGH7.2A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is ...
CVE-2024-39349CRITICAL9.8A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjans...
CVE-2024-30109MEDIUM6.1HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multipl...
CVE-2024-37282CRITICAL9.8It was identified that under certain specific preconditions, an API key that was originally created with a specific priv...
CVE-2024-6296MEDIUM6.4The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-5864MEDIUM4.3The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-5863MEDIUM5.4The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check...
CVE-2024-37137MEDIUM5.5Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnera...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now