2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11265MEDIUM4.3The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosu...
CVE-2024-11188MEDIUM6.1The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Word...
CVE-2024-11426MEDIUM6.4The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-11408MEDIUM6.4The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortc...
CVE-2024-11387MEDIUM6.4The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' sho...
CVE-2024-11361MEDIUM6.1The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-11332MEDIUM6.4The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable t...
CVE-2024-10880MEDIUM6.1The JobBoardWP – Job Board Listings and Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
CVE-2024-10606MEDIUM4.3The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-9223MEDIUM4.3The WPDash Notes plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on ...
CVE-2024-11463MEDIUM6.1The DeBounce Email Validator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'from', 'to', ...
CVE-2024-11362MEDIUM6.1The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v...
CVE-2024-10886MEDIUM6.4The Tribute Testimonials – WordPress Testimonial Grid/Slider plugin for WordPress is vulnerable to Stored Cross-Site Scr...
CVE-2024-10874MEDIUM6.4The Quotes llama plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quotes-llama' short...
CVE-2024-10869MEDIUM6.1The WordPress Brute Force Protection – Stop Brute Force Attacks plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-10868MEDIUM4.3The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in...
CVE-2024-10537MEDIUM4.3The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of dat...
CVE-2024-10216MEDIUM4.3The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-10116MEDIUM5.4The Twitter Follow Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'username' parameter...
CVE-2024-41761MEDIUM5.3IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of serv...
CVE-2024-11586MEDIUM4Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.
CVE-2024-8360MEDIUM6.8Visteon Infotainment REFLASH_DDU_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability a...
CVE-2024-8359MEDIUM6.8Visteon Infotainment REFLASH_DDU_FindFile Command Injection Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2024-8358MEDIUM6.8Visteon Infotainment UPDATES_ExtractFile Command Injection Remote Code Execution Vulnerability. This vulnerability allow...
CVE-2024-8355MEDIUM6.8Visteon Infotainment System DeviceManager iAP Serial Number SQL Injection Vulnerability. This vulnerability allows physi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now