2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11782MEDIUM5.4The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' short...
CVE-2024-11325MEDIUM5.2The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add...
CVE-2024-11866MEDIUM6.4The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map'...
CVE-2024-11844MEDIUM4.3The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-11898MEDIUM5.4The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin...
CVE-2024-11853MEDIUM6.4The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versio...
CVE-2024-11805MEDIUM6.1The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ...
CVE-2024-11732MEDIUM6.5The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter i...
CVE-2024-11707MEDIUM6.1The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in...
CVE-2024-11461MEDIUM6.1The Form Data Collector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in...
CVE-2024-11453MEDIUM5.4The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerab...
CVE-2024-9058MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-49421MEDIUM4.3Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in ...
CVE-2024-49419MEDIUM4.3Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows...
CVE-2024-49418MEDIUM6.5Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows...
CVE-2024-49416MEDIUM5.5Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get ...
CVE-2024-49412MEDIUM5.5Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for dis...
CVE-2024-49411MEDIUM4.6Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary p...
CVE-2024-10893MEDIUM4.8The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could al...
CVE-2024-10484MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-9694MEDIUM6.4The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in...
CVE-2024-9197MEDIUM4.9A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B f...
CVE-2024-53988MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53987MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...
CVE-2024-53986MEDIUM6.1rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnera...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now