2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11238MEDIUM5.3A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPre...
CVE-2024-1240MEDIUM6.1An open redirection vulnerability exists in pyload/pyload version 0.5.0. The vulnerability is due to improper handling o...
CVE-2024-1097MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs...
CVE-2024-11182MEDIUM6.1An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail messag...
CVE-2024-0875MEDIUM4.8A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malici...
CVE-2024-0787MEDIUM5.9phpIPAM version 1.5.1 contains a vulnerability where an attacker can bypass the IP block mechanism to brute force passwo...
CVE-2024-8979MEDIUM5.7The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-8978MEDIUM5.7The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-9529MEDIUM6.6The Secure Custom Fields WordPress plugin before 6.3.9, Secure Custom Fields WordPress plugin before 6.3.6.3, Advanced C...
CVE-2024-8961MEDIUM5.4The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for Wo...
CVE-2024-10825MEDIUM6.1The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
CVE-2024-10104MEDIUM5.9The Jobs for WordPress plugin before 2.7.8 does not sanitise and escape some of its Job settings, which could allow high...
CVE-2024-9356MEDIUM6.1The Yotpo: Product & Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-42499MEDIUM5.3Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior t...
CVE-2024-39610MEDIUM6.1Cross-site scripting vulnerability exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an...
CVE-2024-10793MEDIUM6.1The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all v...
CVE-2024-10582MEDIUM4.3The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modifi...
CVE-2024-10260MEDIUM6.1The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, a...
CVE-2024-10113MEDIUM5.4The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-9609MEDIUM6.1The LearnPress Export Import – WordPress extension for LearnPress plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-10897MEDIUM4.3The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing c...
CVE-2024-52613MEDIUM5.5A heap-based buffer under-read in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Servic...
CVE-2024-49776MEDIUM6.5A negative-size-param in tsMuxer version nightly-2024-04-05-01-53-02 allows attackers to cause Denial of Service (DoS) v...
CVE-2024-41217MEDIUM6.5A heap-based buffer overflow in tsMuxer version nightly-2024-05-10-02-00-45 allows attackers to cause Denial of Service ...
CVE-2024-41206MEDIUM6.5A stack-based buffer over-read in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Information Disc...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now