2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-54266MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle Image...
CVE-2024-54259MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS DELUCKS SEO delu...
CVE-2024-54252MEDIUM6.3Missing Authorization vulnerability in DOTonPAPER Pinpoint Booking System booking-system allows Exploiting Incorrectly C...
CVE-2024-54250MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in prodigycommerce Pr...
CVE-2024-54246MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 FAQs faqs...
CVE-2024-54245MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Clients c...
CVE-2024-54244MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Easy Repl...
CVE-2024-54243MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Echoza ec...
CVE-2024-54242MEDIUM6.5Missing Authorization vulnerability in appsbd Simple Notification simple-notification allows Exploiting Incorrectly Conf...
CVE-2024-54241MEDIUM6.5Missing Authorization vulnerability in Appsbd Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notific...
CVE-2024-47984MEDIUM6.5Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could p...
CVE-2024-24902MEDIUM5.5Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local a...
CVE-2024-48008MEDIUM6.5Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote att...
CVE-2024-9608MEDIUM6.1The MyParcel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg withou...
CVE-2024-11827MEDIUM6.4The Out of the Block: OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's o...
CVE-2024-11012MEDIUM6.3The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via...
CVE-2024-12465MEDIUM6.4The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-12421MEDIUM6.5The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode e...
CVE-2024-12420MEDIUM6.5The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to arbitrary shortcode exec...
CVE-2024-12417MEDIUM6.5The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to,...
CVE-2024-12414MEDIUM4.3The Themify Store Locator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-12309MEDIUM5.3The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Referen...
CVE-2024-12042MEDIUM5.4The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-11911MEDIUM4.3The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability c...
CVE-2024-11910MEDIUM5.4The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search blo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now