2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10498MEDIUM6.9CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a...
CVE-2024-10497HIGH8.8CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t...
CVE-2024-13378MEDIUM5.4The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i...
CVE-2024-13377HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi...
CVE-2024-12476HIGH8.4CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos...
CVE-2024-12399HIGH7.1CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-12370MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-11425HIGH8.7CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe...
CVE-2024-11139MEDIUM4.6CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l...
CVE-2024-13386MEDIUM6.4The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ...
CVE-2024-13367MEDIUM6.5The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do...
CVE-2024-13366MEDIUM6.1The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio...
CVE-2024-12637MEDIUM5.3The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-12598MEDIUM6.4The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ p...
CVE-2024-12508MEDIUM6.4The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g...
CVE-2024-12466MEDIUM6.1The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all v...
CVE-2024-12203MEDIUM4.4The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in ...
CVE-2024-13333HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-11146MEDIUM6.3TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-...
CVE-2024-10799MEDIUM6.5The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via th...
CVE-2024-13434MEDIUM6.1The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramete...
CVE-2024-13401MEDIUM6.4The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_pay...
CVE-2024-13398MEDIUM6.4The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for...
CVE-2024-51462MEDIUM5.3IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter value...
CVE-2024-52363HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now