2024 CVE Vulnerabilities

39,240 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-6266CRITICAL9.8A vulnerability classified as critical has been found in Pear Admin Boot up to 2.0.2. Affected is an unknown function of...
CVE-2024-38319HIGH8.8IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted s...
CVE-2024-5443CRITICAL9.8CVE-2024-4320 describes a vulnerability in the parisneo/lollms software, specifically within the `ExtensionBuilder().bui...
CVE-2024-6253CRITICAL9.8A vulnerability was found in itsourcecode Online Food Ordering System 1.0 and classified as critical. Affected by this i...
CVE-2024-6252MEDIUM6.1A vulnerability has been found in Zorlan SkyCaiji up to 2.8 and classified as problematic. Affected by this vulnerabilit...
CVE-2024-6251MEDIUM6.1A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the...
CVE-2024-38379MEDIUM4.8Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these ...
CVE-2024-5596MEDIUM6.3The ARMember Premium plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, ...
CVE-2024-4940MEDIUM6.1An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows a...
CVE-2024-3593MEDIUM5.4The UberMenu plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8....
CVE-2024-4874MEDIUM4.3The Bricks Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc...
CVE-2024-21519HIGH7.2This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via...
CVE-2024-21518HIGH7.2This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace...
CVE-2024-21517MEDIUM6.1This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirec...
CVE-2024-21516MEDIUM4.7This affects versions of the package opencart/opencart from 4.0.0.0 and before 4.1.0.0. A reflected XSS issue was identi...
CVE-2024-21515MEDIUM4.7This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the filenam...
CVE-2024-21514HIGH8.1This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido p...
CVE-2024-5966MEDIUM5.4The Grey Opaque theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them...
CVE-2024-5965MEDIUM5.4The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's ...
CVE-2024-5791MEDIUM6.1The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site ...
CVE-2024-5346MEDIUM5.4The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the UX Countdown, Video Button, UX Vid...
CVE-2024-4313MEDIUM5.4The Table Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter...
CVE-2024-2484MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Services and Post T...
CVE-2024-6120MEDIUM6.5The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to ...
CVE-2024-37694Rejected reason: This submission has been rejected by the CNA of record. Authentication is user configurable as describ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now