2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12590MEDIUM6.4The WP Youtube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in all v...
CVE-2024-12559MEDIUM5.3The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-12557MEDIUM6.1The Transporters.io plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-12541MEDIUM5.4The Chative Live chat and Chatbot plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
CVE-2024-12538MEDIUM4.3The Duplicate Post, Page and Any Custom Post plugin for WordPress is vulnerable to Sensitive Information Exposure in all...
CVE-2024-12528MEDIUM6.4The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-12419MEDIUM6.5The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to arbitrar...
CVE-2024-12098MEDIUM6.1The ARS Affiliate Page Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'utm_keyword'...
CVE-2024-11934MEDIUM6.4The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-11899MEDIUM6.4The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short...
CVE-2024-11777MEDIUM6.4The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for...
CVE-2024-11437MEDIUM4.9The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a...
CVE-2024-54764MEDIUM6.5An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit...
CVE-2024-54763MEDIUM6.5An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti...
CVE-2024-53936MEDIUM6.3The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any applicati...
CVE-2024-53935MEDIUM6.5The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables ...
CVE-2024-53933MEDIUM6.3The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Andr...
CVE-2024-51741MEDIUM4.4Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat...
CVE-2024-55075MEDIUM5.3Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh...
CVE-2024-55408MEDIUM5.3An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti...
CVE-2024-46209MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke...
CVE-2024-35498MEDIUM6.1A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-55626MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-46073MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is...
CVE-2024-56769MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now