2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10892MEDIUM5.4The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX actions, which could a...
CVE-2024-56170MEDIUM5.3A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant ...
CVE-2024-56169MEDIUM5.3A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are ...
CVE-2024-12698MEDIUM6.5An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-4...
CVE-2024-12596MEDIUM4.3The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post del...
CVE-2024-12449MEDIUM6.4The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-12250MEDIUM5.3The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all...
CVE-2024-12061MEDIUM4.3The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc...
CVE-2024-11254MEDIUM6.1The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the d...
CVE-2024-12513MEDIUM6.4The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONT...
CVE-2024-12500MEDIUM6.4The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-11881MEDIUM6.4The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywavefor...
CVE-2024-11748MEDIUM6.4The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'taeggie-feed' short...
CVE-2024-11439MEDIUM6.4The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'scancircle' shortcode...
CVE-2024-10973MEDIUM5.7A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGr...
CVE-2024-56142MEDIUM6.5pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerabilit...
CVE-2024-52792MEDIUM6.5LDAP Account Manager (LAM) is a php webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LD...
CVE-2024-55059MEDIUM6.1A stored HTML Injection vulnerability was identified in PHPGurukul Online Birth Certificate System v1.0 in /user/certifi...
CVE-2024-55058MEDIUM4.3An insecure direct object reference (IDOR) vulnerability was discovered in PHPGurukul Online Birth Certificate System v1...
CVE-2024-55057MEDIUM5.4Phpgurukul Online Birth Certificate System 1.0 suffers from insufficient password requirements which can lead to unautho...
CVE-2024-55056MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in Phpgurukul Online Birth Certificate System 1.0 in /u...
CVE-2024-12539MEDIUM6.5An issue was discovered where improper authorization controls affected certain queries that could allow a malicious acto...
CVE-2024-11993MEDIUM6.1Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.38, and Liferay DXP 7.4 GA thro...
CVE-2024-55514MEDIUM6.3A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue...
CVE-2024-56139MEDIUM6.9pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now