2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11451MEDIUM6.4The Zooom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zooom' shortcode in all ve...
CVE-2024-11436MEDIUM6.1The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! plu...
CVE-2024-11353MEDIUM4.3The SMS for Lead Capture Forms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-11329MEDIUM6.1The Comfino Payment Gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q...
CVE-2024-10046MEDIUM6.1The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-54138MEDIUM6.1NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to it...
CVE-2024-7875MEDIUM5.3Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks...
CVE-2024-7874MEDIUM5.3Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks...
CVE-2024-12326MEDIUM6.1Jirafeau normally prevents browser preview for SVG files due to the possibility that manipulated SVG files could be expl...
CVE-2024-0139MEDIUM4.4NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A suc...
CVE-2024-47791MEDIUM5.3Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possibl...
CVE-2024-47146MEDIUM6.5Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial nu...
CVE-2024-52558MEDIUM6.9The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP requ...
CVE-2024-48703MEDIUM4.8PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard....
CVE-2024-47043MEDIUM5.3Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial n...
CVE-2024-55268MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul CO...
CVE-2024-48866MEDIUM5.3An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating sys...
CVE-2024-50677MEDIUM6.1A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or ...
CVE-2024-30129MEDIUM5.3The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the ...
CVE-2024-42196MEDIUM5.5HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP ...
CVE-2024-54213MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zionbuilder ZionBu...
CVE-2024-54212MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ...
CVE-2024-54211MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl...
CVE-2024-54210MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codexshaper Advanc...
CVE-2024-54207MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Marka WordPress...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now