2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11814MEDIUM6.1The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-5020MEDIUM6.4Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScrip...
CVE-2024-11880MEDIUM6.4The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-10787MEDIUM4.3The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to...
CVE-2024-11903MEDIUM6.4The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in al...
CVE-2024-11769MEDIUM6.4The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'f...
CVE-2024-11466MEDIUM6.1The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't...
CVE-2024-10664MEDIUM4.3The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modif...
CVE-2024-45717MEDIUM4.8The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of t...
CVE-2024-12123MEDIUM5.3A hidden field manipulation vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authent...
CVE-2024-12099MEDIUM4.3The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in a...
CVE-2024-10885MEDIUM5.4The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's...
CVE-2024-11897MEDIUM5.4The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting ...
CVE-2024-11813MEDIUM6.1The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-11807MEDIUM6.1The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' paramet...
CVE-2024-11747MEDIUM6.4The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortc...
CVE-2024-11093MEDIUM5.5The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due ...
CVE-2024-10832MEDIUM6.1The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secre...
CVE-2024-10663MEDIUM4.3The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-45206MEDIUM6.5A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests t...
CVE-2024-45204MEDIUM4.3A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak N...
CVE-2024-42457MEDIUM6.5A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by le...
CVE-2024-42451MEDIUM6.5A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. Th...
CVE-2024-11985MEDIUM4.4An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2...
CVE-2024-11479MEDIUM5.1A HTML Injection vulnerability was identified in Issuetrak version 17.1 that could be triggered by an authenticated user...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now