2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-11623MEDIUM4.8Authentik project is vulnerable to Stored XSS attacks through uploading crafted SVG files that are used as application i...
CVE-2024-13699MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter...
CVE-2024-27137MEDIUM5.3In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration...
CVE-2024-40891HIGH8.8**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le...
CVE-2024-40890HIGH8.8**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL...
CVE-2024-13733MEDIUM5.4The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-13529MEDIUM6.5The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of ...
CVE-2024-13510MEDIUM6.1The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5....
CVE-2024-13356MEDIUM6.5The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-13403MEDIUM5.4The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2024-13514MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions u...
CVE-2024-12046MEDIUM4.3The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u...
CVE-2024-10239HIGH7.2A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6 . An attacker with admin...
CVE-2024-10238HIGH7.2A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can uplo...
CVE-2024-10237HIGH7.2There is a vulnerability in the BMC firmware image authentication design at Supermicro MBD-X12DPG-OA6 . An attacker ...
CVE-2024-13607MEDIUM4.3The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object ...
CVE-2024-12597MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b...
CVE-2024-13332MEDIUM6.1The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13331MEDIUM6.1The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back...
CVE-2024-13330HIGH7.1The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13329HIGH7.1The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13328MEDIUM6.1The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13327MEDIUM6.1The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13326MEDIUM6.1The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13325MEDIUM6.1The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now