2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10849MEDIUM6.4The NewsMash theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versio...
CVE-2024-10692MEDIUM4.3The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Informatio...
CVE-2024-10689MEDIUM4.3The XLTab – Accordions and Tabs for Elementor Page Builder plugin for WordPress is vulnerable to Information Exposure in...
CVE-2024-10320MEDIUM6.4The Cookielay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cookielay shortcode in ...
CVE-2024-11201MEDIUM6.4The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo...
CVE-2024-10551MEDIUM4.8The Sticky Social Icons WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could al...
CVE-2024-10480MEDIUM4.3The 3DPrint Lite WordPress plugin before 2.1 does not have CSRF check in place when updating its settings, which could a...
CVE-2024-11379MEDIUM6.1The Broadcast plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'do_check' parameter in all v...
CVE-2024-9769MEDIUM4.8The Video Gallery – Best WordPress YouTube Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-10836MEDIUM6.1The Flixita theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in all versions u...
CVE-2024-10247MEDIUM4.9The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection...
CVE-2024-49041MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-11149MEDIUM5.5In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.
CVE-2024-53457MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows ...
CVE-2024-10933MEDIUM5.5In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid ...
CVE-2024-54128MEDIUM4.6Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a f...
CVE-2024-53846MEDIUM5.5OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainl...
CVE-2024-54001MEDIUM5.5Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the...
CVE-2024-53471MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3...
CVE-2024-53470MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA...
CVE-2024-12247MEDIUM4.3Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updat...
CVE-2024-12232MEDIUM6.1A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulner...
CVE-2024-10716MEDIUM4.8Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.
CVE-2024-11942MEDIUM5.9A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.
CVE-2024-54679MEDIUM6.5CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now