2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-56378MEDIUM4.3libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine functio...
CVE-2024-12897MEDIUM5.3A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has ...
CVE-2024-12896MEDIUM6.9A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222 and clas...
CVE-2024-56314MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated user...
CVE-2024-56313MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated ...
CVE-2024-56312MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenti...
CVE-2024-12893MEDIUM5.4A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar up to 2.9. Affected by this ...
CVE-2024-12892MEDIUM5.4A vulnerability classified as problematic was found in code-projects Online Exam Mastering System 1.0. Affected by this ...
CVE-2024-11852MEDIUM4.3The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for...
CVE-2024-51464MEDIUM4.3IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially craft...
CVE-2024-51463MEDIUM5.4IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker ...
CVE-2024-12883MEDIUM6.1A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as problematic. Affected by this vu...
CVE-2024-12875MEDIUM4.9The Easy Digital Downloads – eCommerce Payments and Subscriptions made easy plugin for WordPress is vulnerable to Direct...
CVE-2024-12591MEDIUM6.4The MagicPost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wb_share_social shortco...
CVE-2024-12558MEDIUM6.5The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to unauthorized access of da...
CVE-2024-12408MEDIUM6.1The WP on AWS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST data in all versions up to...
CVE-2024-11722MEDIUM5.9The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all ...
CVE-2024-11688MEDIUM6.1The LaTeX2HTML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ver' or 'date' parameter in...
CVE-2024-10453MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-9545MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-12588MEDIUM5.4The Shortcodes and extra features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-11808MEDIUM6.1The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' ...
CVE-2024-10797MEDIUM4.3The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and...
CVE-2024-12697MEDIUM6.4The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1...
CVE-2024-12635MEDIUM6.5The WP Docs plugin for WordPress is vulnerable to time-based SQL Injection via the 'dir_id' parameter in all versions up...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now