2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11488MEDIUM6.1A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown proces...
CVE-2024-11486MEDIUM4.3A vulnerability, which was classified as problematic, was found in Code4Berry Decoration Management System 1.0. This aff...
CVE-2024-52471MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppar...
CVE-2024-51209MEDIUM5.4Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to...
CVE-2024-52597MEDIUM6.12FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Versions prior...
CVE-2024-11154MEDIUM4.3The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner...
CVE-2024-11406MEDIUM6.9Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS ...
CVE-2024-11404MEDIUM5.5Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basi...
CVE-2024-10520MEDIUM5.3The WP Project Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabili...
CVE-2024-48899MEDIUM4.3A vulnerability was found in Moodle. Additional checks are required to ensure users can only fetch the list of course ba...
CVE-2024-45691MEDIUM5.4A flaw was found in Moodle. When restricting access to a lesson activity with a password, certain passwords could be byp...
CVE-2024-45689MEDIUM6.5A flaw was found in Moodle. Dynamic tables did not enforce capability checks, which resulted in users having the ability...
CVE-2024-10872MEDIUM5.4The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `template-post-c...
CVE-2024-11179MEDIUM6.5The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to SQL Injection via t...
CVE-2024-10891MEDIUM6.4The Save as PDF Plugin by Pdfcrowd plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 's...
CVE-2024-10665MEDIUM5.4The Yaad Sarig Payment Gateway For WC plugin for WordPress is vulnerable to unauthorized modification & access of data d...
CVE-2024-11176MEDIUM5.3Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access o...
CVE-2024-10126MEDIUM4.3Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7...
CVE-2024-52033MEDIUM5.3Exposure of sensitive system information to an unauthorized control sphere issue exists in Rakuten Turbo 5G firmware ver...
CVE-2024-47865MEDIUM5.3Missing authentication for critical function vulnerability exists in Rakuten Turbo 5G firmware version V1.3.18 and earli...
CVE-2024-9239MEDIUM6.1The Booster for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_q...
CVE-2024-8726MEDIUM6.1The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ...
CVE-2024-11277MEDIUM6.1The 404 Solution plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to, an...
CVE-2024-10365MEDIUM4.3The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-9653MEDIUM6.1The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Reflected Cross-Sit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now