2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-37098CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects Blo...
CVE-2024-28830LOW2.7Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <...
CVE-2024-5215MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multip...
CVE-2024-5573MEDIUM5.9The Easy Table of Contents WordPress plugin before 2.0.66 does not sanitise and escape some of its settings, which could...
CVE-2024-5473MEDIUM4The Simple Photoswipe WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-5332MEDIUM5.4The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Ca...
CVE-2024-5199MEDIUM5.4The Spotify Play Button WordPress plugin through 1.0 does not validate and escape some of its shortcode attributes befor...
CVE-2024-5169MEDIUM4.8The Video Widget WordPress plugin through 1.2.3 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-5071MEDIUM6.5The Bookster WordPress plugin through 1.1.0 allows adding sensitive parameters when validating appointments allowing at...
CVE-2024-4959MEDIUM4.8The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all...
CVE-2024-4957MEDIUM4.3The Frontend Checklist WordPress plugin through 2.3.2 does not sanitise and escape some of its settings, which could all...
CVE-2024-4758HIGH7.6The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, whi...
CVE-2024-4106MEDIUM5.3A vulnerability has been found in FAST/TOOLS and CI Server. The affected products have built-in accounts with no passwor...
CVE-2024-4105MEDIUM5.8A vulnerability has been found in FAST/TOOLS and CI Server. The affected product's WEB HMI server's function to process ...
CVE-2024-3633MEDIUM5.4The WebP & SVG Support WordPress plugin through 1.4.0 does not sanitise uploaded SVG files, which could allow users with...
CVE-2024-36802Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2024-34581HIGH7.3The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a ...
CVE-2024-34580MEDIUM5.3Apache XML Security for C++ through 2.0.4 implements the XML Signature Syntax and Processing (XMLDsig) specification wit...
CVE-2024-21520MEDIUM6.1Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_lon...
CVE-2024-37141LOW3.5Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerab...
CVE-2024-37140HIGH8.8Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection v...
CVE-2024-37139MEDIUM6.5Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a ...
CVE-2024-37138MEDIUM6.8Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path t...
CVE-2024-27867MEDIUM4.3An authentication issue was addressed with improved state management. This issue is fixed in AirPods Firmware Update 6A3...
CVE-2024-5181CRITICAL9.8A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the applica...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now