2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45841MEDIUM6.5Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/E...
CVE-2024-11779MEDIUM6.4The WIP WooCarousel Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wip_woocaro...
CVE-2024-11420MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Contact Info Block link parameter i...
CVE-2024-11341MEDIUM4.3The Simple Redirection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-11324MEDIUM6.1The Accounting for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-10848MEDIUM6.4The NewsMunch theme for WordPress is vulnerable to Stored Cross-Site Scripting via a malicious display name in all versi...
CVE-2024-10777MEDIUM4.3The AnyWhere Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, ...
CVE-2024-10056MEDIUM6.4The Contact Form Builder by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's liv...
CVE-2024-10937MEDIUM5.3The Related Posts, Inline Related Posts, Contextual Related Posts, Related Content By PickPlugins plugin for WordPress i...
CVE-2024-42195MEDIUM6.8HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary H...
CVE-2024-10178MEDIUM5.4The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-10881MEDIUM6.4The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lunaradio' shortcode in...
CVE-2024-12183MEDIUM5.4A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS ...
CVE-2024-12182MEDIUM5.4A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some ...
CVE-2024-12181MEDIUM5.4A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown fun...
CVE-2024-12180MEDIUM5.4A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file...
CVE-2024-54675MEDIUM6.1app/webroot/js/workflows-editor/workflows-editor.js in MISP through 2.5.2 has stored XSS in the editor interface for an ...
CVE-2024-54674MEDIUM6.1app/View/GalaxyClusters/cluster_export_misp_galaxy.ctp in MISP through 2.5.2 has stored XSS when exporting custom cluste...
CVE-2024-51210MEDIUM5.3Firepad through 1.5.11 allows remote attackers, who have knowledge of a pad ID, to retrieve both the current text of a d...
CVE-2024-12196MEDIUM6.5Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated...
CVE-2024-12151MEDIUM5Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users ...
CVE-2024-12148MEDIUM4.3Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authen...
CVE-2024-52676MEDIUM5.4Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/...
CVE-2024-20397MEDIUM5.2A vulnerability in the bootloader of Cisco NX-OS Software could allow an unauthenticated attacker with physical access t...
CVE-2024-54132MEDIUM6.3The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now