2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12260MEDIUM6.1The Ultimate Endpoints With Rest Api plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page'...
CVE-2024-12258MEDIUM6.1The WP Service Payment Form With Authorize.net plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2024-11914MEDIUM6.4The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-11901MEDIUM6.4The PowerBI Embed Reports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MO_API_POW...
CVE-2024-11683MEDIUM6.1The Newsletter Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'token_type' p...
CVE-2024-11442MEDIUM6.4The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11433MEDIUM6.4The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11430MEDIUM6.5The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' short...
CVE-2024-11427MEDIUM6.4The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortco...
CVE-2024-11419MEDIUM6.1The Password for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-11417MEDIUM6.1The dejure.org Vernetzungsfunktion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2024-11413MEDIUM6.4The HostFact bestelformulier integratie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-11279MEDIUM6.1The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-55659MEDIUM5.4SiYuan is a personal knowledge management system. Prior to version 3.1.16, the `/api/asset/upload` endpoint in Siyuan is...
CVE-2024-55652MEDIUM6.5PenDoc is a penetration testing reporting application. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an atta...
CVE-2024-54531MEDIUM5.5The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2. An app may be able to ...
CVE-2024-54527MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macO...
CVE-2024-54526MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS...
CVE-2024-54524MEDIUM5.5A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2. A malicious app may ...
CVE-2024-54513MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS S...
CVE-2024-54510MEDIUM5.1A race condition was addressed with improved locking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, ma...
CVE-2024-54504MEDIUM5.5A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia...
CVE-2024-54503MEDIUM4.2An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.2 and i...
CVE-2024-54502MEDIUM6.5The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7....
CVE-2024-54501MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now