2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12218MEDIUM6.1The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-12206MEDIUM4.3The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers...
CVE-2024-12122MEDIUM6.1The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions ...
CVE-2024-12067MEDIUM6.5The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injecti...
CVE-2024-11929MEDIUM6.4The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp...
CVE-2024-11907MEDIUM6.4The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_ifram...
CVE-2024-11815MEDIUM6.1The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
CVE-2024-11686MEDIUM6.1The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts...
CVE-2024-11328MEDIUM6.1The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ...
CVE-2024-13153MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widg...
CVE-2024-43662MEDIUM5.3The <redacted>.exe or <redacted>.exe CGI binary can be used to upload arbitrary files to /tmp/upload/ or /tmp/ respectiv...
CVE-2024-12806MEDIUM4.9A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an ar...
CVE-2024-13041MEDIUM5.4An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 pr...
CVE-2024-6324MEDIUM4.3An issue was discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 17.5.5, starting from 17.6 pr...
CVE-2024-12736MEDIUM6.1The BU Section Editing WordPress plugin through 0.9.9 does not sanitise and escape a parameter before outputting it back...
CVE-2024-12731MEDIUM6.1The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-12717MEDIUM4.8The Aklamator INfeed WordPress plugin through 2.0.0 does not sanitise and escape some of its settings, which could allow...
CVE-2024-12715MEDIUM6.1The Asgard Security Scanner WordPress plugin through 0.7 does not sanitise and escape a parameter before outputting it b...
CVE-2024-12714MEDIUM6.1The Backlink Monitoring Manager WordPress plugin through 0.1.3 does not sanitise and escape a parameter before outputtin...
CVE-2024-10815MEDIUM4.2The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it ...
CVE-2024-56827MEDIUM5.6A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe...
CVE-2024-56826MEDIUM5.6A flaw was found in the OpenJPEG project. A heap buffer overflow condition may be triggered when certain options are spe...
CVE-2024-13213MEDIUM5.4A vulnerability classified as problematic was found in SingMR HouseRent 1.0. This vulnerability affects unknown code of ...
CVE-2024-13209MEDIUM5.4A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function o...
CVE-2024-13205MEDIUM5.4A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been rated as problematic. Affected by this issue...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now