2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32946MEDIUM5.9A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitte...
CVE-2024-3935MEDIUM6.5In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridg...
CVE-2024-9388MEDIUM5.4The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-50512MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows...
CVE-2024-8444MEDIUM5.4The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross...
CVE-2024-10223MEDIUM6.4The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-8871MEDIUM6.1The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scr...
CVE-2024-10399MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-9886MEDIUM6.4The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcod...
CVE-2024-9885MEDIUM6.4The Widget or Sidebar Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'side...
CVE-2024-9884MEDIUM6.4The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode...
CVE-2024-8792MEDIUM6.1The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que...
CVE-2024-8627MEDIUM5.4The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all ...
CVE-2024-10503MEDIUM6.1A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some ...
CVE-2024-50348MEDIUM5.4InstantCMS is a free and open source content management system. In photo upload function in the photo album page there i...
CVE-2024-50454MEDIUM5.3Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce...
CVE-2024-50425MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking Syste...
CVE-2024-50424MEDIUM6.5Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access...
CVE-2024-50423MEDIUM5.4Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access...
CVE-2024-50422MEDIUM5.3Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S...
CVE-2024-50421MEDIUM5.3Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-pa...
CVE-2024-48572MEDIUM5.3A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres...
CVE-2024-48461MEDIUM4.8Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitr...
CVE-2024-10491MEDIUM5.3A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in...
CVE-2024-25566MEDIUM6.1An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect UR...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now