2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-13385MEDIUM6.4The JSM Screenshot Machine Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-13317MEDIUM4.3The ShipWorks Connector for Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
CVE-2024-12696MEDIUM6.4The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-12385MEDIUM6.1The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-9020MEDIUM5.4The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef...
CVE-2024-13516MEDIUM6.1The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet...
CVE-2024-13515MEDIUM6.1The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-12071MEDIUM5.3The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab...
CVE-2024-11923MEDIUM5.5Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo...
CVE-2024-57252MEDIUM4.3OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr...
CVE-2024-57035CRITICAL9.8WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
CVE-2024-57033MEDIUM6.1WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
CVE-2024-57372MEDIUM6.1Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform...
CVE-2024-57370MEDIUM6.1Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se...
CVE-2024-57369MEDIUM6.4Clickjacking vulnerability in typecho v1.2.1.
CVE-2024-57034CRITICAL9.8WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
CVE-2024-57032CRITICAL9.8WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the v...
CVE-2024-57031CRITICAL9.8WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.
CVE-2024-57030HIGH8.1Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-52870HIGH7.1Teradata Vantage Editor 1.0.1 is mostly intended for SQL database access and docs.teradata.com access, but provides unin...
CVE-2024-13026MEDIUM6.1A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ...
CVE-2024-12757HIGH8.8Nedap Librix Ecoreader is missing authentication for critical functions that could allow an unauthenticated attacker ...
CVE-2024-54681LOW3.5Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att...
CVE-2024-53683MEDIUM5.6A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An...
CVE-2024-45832MEDIUM4.3Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now