2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7424MEDIUM5.4The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to unauthorized modification of and access t...
CVE-2024-49501MEDIUM5.7Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. If this vulnerability is ...
CVE-2024-21510MEDIUM5.4Versions of the package sinatra from 0.0.0 are vulnerable to Reliance on Untrusted Inputs in a Security Decision via the...
CVE-2024-10620MEDIUM6.9A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part...
CVE-2024-10605MEDIUM6.5A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as problematic. This...
CVE-2024-6480MEDIUM5.4The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'no_...
CVE-2024-6479MEDIUM6.5The SIP Reviews Shortcode for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'no_of_reviews' at...
CVE-2024-10598MEDIUM6.5A vulnerability classified as critical was found in Tongda OA 11.2/11.3/11.4/11.5/11.6. This vulnerability affects unkno...
CVE-2024-50802MEDIUM6A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle...
CVE-2024-50801MEDIUM6A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controlle...
CVE-2024-10573MEDIUM6.7An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may writ...
CVE-2024-50347MEDIUM6.3Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is a...
CVE-2024-51430MEDIUM6.4Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker t...
CVE-2024-50354MEDIUM5.5gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deseriali...
CVE-2024-8553MEDIUM6.3A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authent...
CVE-2024-8934MEDIUM6.5A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI)...
CVE-2024-10454MEDIUM6.1Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerabilit...
CVE-2024-43933MEDIUM4.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.Ap...
CVE-2024-43930MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects...
CVE-2024-30149MEDIUM6.5HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.
CVE-2024-9446MEDIUM6.4The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor ...
CVE-2024-9434MEDIUM6.1The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2024-9430MEDIUM5.3The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized acces...
CVE-2024-9165MEDIUM6.4The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-9700MEDIUM5.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure D...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now