2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12262MEDIUM6.1The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all ver...
CVE-2024-11975MEDIUM6.1The Reactflow Visitor Recording and Heatmaps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via th...
CVE-2024-11938MEDIUM6.4The One Click Upsell Funnel for WooCommerce – Funnel Builder for WordPress, Create WooCommerce Upsell, Post-Purchase Up...
CVE-2024-11682MEDIUM6.1The G Web Pro Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'q' parameter i...
CVE-2024-11287MEDIUM6.1The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg wit...
CVE-2024-11196MEDIUM6.4The Multi-column Tag Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mctagmap sho...
CVE-2024-11607MEDIUM6.1The GTPayment Donations WordPress plugin through 1.0.0 does not have CSRF check in some places, and is missing sanitisat...
CVE-2024-12846MEDIUM4.8A vulnerability, which was classified as problematic, has been found in Emlog Pro up to 2.4.1. Affected by this issue is...
CVE-2024-11811MEDIUM6.1The Feedify – Web Push Notifications plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'platf...
CVE-2024-12845MEDIUM6.1A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unkno...
CVE-2024-56359MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink c...
CVE-2024-56358MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have...
CVE-2024-56357MEDIUM6.1grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could ha...
CVE-2024-40875MEDIUM5.9There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52...
CVE-2024-12844MEDIUM6.1A vulnerability classified as problematic has been found in Emlog Pro up to 2.4.1. Affected is an unknown function of th...
CVE-2024-12843MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been rated as problematic. This issue affects some unknown pr...
CVE-2024-56331MEDIUM6.8Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacke...
CVE-2024-55341MEDIUM4.7A stored cross-site scripting (XSS) vulnerability in Piranha CMS 11.1 allows remote attackers to execute arbitrary JavaS...
CVE-2024-12842MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been declared as problematic. This vulnerability affects unkn...
CVE-2024-55342MEDIUM4.7A file upload functionality in Piranha CMS 11.1 allows authenticated remote attackers to upload a crafted PDF file to /m...
CVE-2024-12841MEDIUM6.1A vulnerability was found in Emlog Pro up to 2.4.1. It has been classified as problematic. This affects an unknown part ...
CVE-2024-55471MEDIUM6.5Oqtane Framework is vulnerable to Insecure Direct Object Reference (IDOR) in Oqtane.Controllers.UserController. This all...
CVE-2024-55186MEDIUM4.3An IDOR (Insecure Direct Object Reference) vulnerability exists in oqtane Framework 6.0.0, allowing a logged-in user to ...
CVE-2024-56355MEDIUM5.4In JetBrains TeamCity before 2024.12 missing Content-Type header in RemoteBuildLogController response could lead to XSS
CVE-2024-56354MEDIUM4.9In JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permission

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now