2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8962MEDIUM5.4The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG F...
CVE-2024-54158MEDIUM5.3In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding
CVE-2024-54157MEDIUM6.5In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector
CVE-2024-54156MEDIUM6.5In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack
CVE-2024-54155MEDIUM5.3In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import wit...
CVE-2024-54153MEDIUM6.5In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query par...
CVE-2024-11854MEDIUM6.4The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stor...
CVE-2024-11814MEDIUM6.1The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-5020MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip...
CVE-2024-11880MEDIUM6.4The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-10787MEDIUM4.3The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to...
CVE-2024-11903MEDIUM6.4The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al...
CVE-2024-11769MEDIUM6.4The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f...
CVE-2024-11466MEDIUM6.1The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't...
CVE-2024-10664MEDIUM4.3The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modif...
CVE-2024-45717MEDIUM4.8The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of t...
CVE-2024-12123MEDIUM5.3A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent...
CVE-2024-12099MEDIUM4.3The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a...
CVE-2024-10885MEDIUM5.4The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's...
CVE-2024-11897MEDIUM5.4The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-11813MEDIUM6.1The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-11807MEDIUM6.1The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet...
CVE-2024-11747MEDIUM6.4The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc...
CVE-2024-11093MEDIUM5.5The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due ...
CVE-2024-10832MEDIUM6.1The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now