2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22037MEDIUM5.7The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permissio...
CVE-2024-11599MEDIUM5.3Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate emai...
CVE-2024-10798MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t...
CVE-2024-10780MEDIUM4.3The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up ...
CVE-2024-10670MEDIUM4.3The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...
CVE-2024-11788MEDIUM6.4The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11786MEDIUM6.4The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c...
CVE-2024-11761MEDIUM6.4The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' s...
CVE-2024-11685MEDIUM6.1The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-11684MEDIUM6.1The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site...
CVE-2024-11458MEDIUM6.1The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter...
CVE-2024-11431MEDIUM6.4The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode...
CVE-2024-11366MEDIUM6.1The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-11333MEDIUM6.4The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode...
CVE-2024-11203MEDIUM5.4The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps i...
CVE-2024-11918MEDIUM4.3The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability ...
CVE-2024-10896MEDIUM5.4The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which ...
CVE-2024-10510MEDIUM4.8The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of ...
CVE-2024-10493MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress pl...
CVE-2024-10473MEDIUM5.4The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing the...
CVE-2024-53008MEDIUM5.3Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulner...
CVE-2024-53858MEDIUM6.5The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that c...
CVE-2024-53260MEDIUM6.8Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first a...
CVE-2024-53855MEDIUM4.3Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management wit...
CVE-2024-53264MEDIUM5.1bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now