2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-55492MEDIUM6.1Winmail Server 4.4 is vulnerable to f_user=%22%3E%3Csvg%20onload Cross Site Scripting (XSS).
CVE-2024-45082MEDIUM5.2IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 could allow a remote attacker to conduct phishing...
CVE-2024-41752MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker ...
CVE-2024-25042MEDIUM6.1IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripti...
CVE-2024-52361MEDIUM5.7IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9  stores user credentials in plain text which can be re...
CVE-2024-56128MEDIUM5.3Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafk...
CVE-2024-50570MEDIUM5A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 th...
CVE-2024-55997MEDIUM6.5Missing Authorization vulnerability in webchunky Order Delivery & Pickup Location Date Time order-delivery-pickup-locati...
CVE-2024-52485MEDIUM6.5Missing Authorization vulnerability in Yudiz Solutions Ltd. WP Menu Image wp-menu-image allows Exploiting Incorrectly Co...
CVE-2024-11926MEDIUM6.5The Travel Booking WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-11291MEDIUM5.3The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-47104MEDIUM6.8IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with auth...
CVE-2024-12554MEDIUM5.4The Peter’s Custom Anti-Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-12454MEDIUM6.1The Affiliate Program Suite — SliceWP Affiliates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
CVE-2024-12340MEDIUM4.3The Animation Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-11295MEDIUM5.3The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ...
CVE-2024-56175MEDIUM6.1In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-56173MEDIUM4.7In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' ...
CVE-2024-10892MEDIUM5.4The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could a...
CVE-2024-56170MEDIUM5.3A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant ...
CVE-2024-56169MEDIUM5.3A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are ...
CVE-2024-12698MEDIUM6.5An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-4...
CVE-2024-12596MEDIUM4.3The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post del...
CVE-2024-12449MEDIUM6.4The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-12250MEDIUM5.3The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now