2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9883MEDIUM4.8The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-9689MEDIUM4.3The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow at...
CVE-2024-7877MEDIUM4.8The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not...
CVE-2024-7876MEDIUM4.8The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not...
CVE-2024-5578MEDIUM4.8The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could ...
CVE-2024-10807MEDIUM4.8A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue aff...
CVE-2024-10340MEDIUM6.4The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'scu' short...
CVE-2024-10806MEDIUM4.8A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulner...
CVE-2024-51498MEDIUM6cobalt is a media downloader that doesn't piss you off. A malicious cobalt instance could serve links with the `javascri...
CVE-2024-50346MEDIUM5.1WebFeed is a lightweight web feed reader extension for Firefox/Chrome. Multiple HTML injection vulnerabilities in WebFee...
CVE-2024-32870MEDIUM5.8Combodo iTop is a simple, web based IT Service Management tool. Server, OS, DBMS, PHP, and iTop info (name, version and ...
CVE-2024-31448MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-sit...
CVE-2024-51502MEDIUM5.1loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the ...
CVE-2024-48059MEDIUM6.1gaizhenbiao/chuanhuchatgpt project, version <=20240802 is vulnerable to stored Cross-Site Scripting (XSS) in WebSocket s...
CVE-2024-48057MEDIUM6.1localai <=2.20.1 is vulnerable to Cross Site Scripting (XSS). When calling the delete model API and passing inappropriat...
CVE-2024-48052MEDIUM6.5In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The re...
CVE-2024-48463MEDIUM6.5Bruno before 1.29.1 uses Electron shell.openExternal without validation (of http or https) for opening windows within th...
CVE-2024-45185MEDIUM5.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 108...
CVE-2024-45086MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when process...
CVE-2024-34891MEDIUM6.8Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrator...
CVE-2024-34885MEDIUM6.8Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrato...
CVE-2024-30618MEDIUM6.1A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary J...
CVE-2024-30617MEDIUM5.4A Cross-Site Request Forgery (CSRF) vulnerability in Chamilo LMS 1.11.26 "/main/social/home.php," allows attackers to in...
CVE-2024-10768MEDIUM5.4A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects...
CVE-2024-51328MEDIUM6.1Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote atta...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now