2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13249MEDIUM5.4Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin...
CVE-2024-13248MEDIUM5.5Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue af...
CVE-2024-13247MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allo...
CVE-2024-13246MEDIUM5.3Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framin...
CVE-2024-13245MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 ...
CVE-2024-13243MEDIUM6.5Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delet...
CVE-2024-13238MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify a...
CVE-2024-13237MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity...
CVE-2024-43176MEDIUM5.4IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should o...
CVE-2024-6155MEDIUM5.4The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Ser...
CVE-2024-5769MEDIUM4.3The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-12819MEDIUM6.4The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortc...
CVE-2024-12621MEDIUM6.4The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' ...
CVE-2024-12618MEDIUM4.3The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...
CVE-2024-12616MEDIUM4.3The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-12605MEDIUM4.3The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-12515MEDIUM6.4The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID ...
CVE-2024-12514MEDIUM6.4The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' short...
CVE-2024-12496MEDIUM6.4The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissi...
CVE-2024-12493MEDIUM6.4The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' sh...
CVE-2024-12491MEDIUM6.4The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_se...
CVE-2024-12394MEDIUM6.1The Action Network plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all ...
CVE-2024-12285MEDIUM6.1The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versi...
CVE-2024-12249MEDIUM4.3The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-12222MEDIUM6.1The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvs...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now