2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8871MEDIUM6.1The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Reflected Cross-Site Scr...
CVE-2024-10399MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-9886MEDIUM6.4The WP Baidu Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'baidu_map' shortcod...
CVE-2024-9885MEDIUM6.4The Widget or Sidebar Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'side...
CVE-2024-9884MEDIUM6.4The T(-) Countdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tminus' shortcode...
CVE-2024-8792MEDIUM6.1The Subscribe to Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_que...
CVE-2024-8627MEDIUM5.4The Ultimate TinyMCE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'field' shortcode in all ...
CVE-2024-10503MEDIUM6.1A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some ...
CVE-2024-50348MEDIUM5.4InstantCMS is a free and open source content management system. In photo upload function in the photo album page there i...
CVE-2024-50454MEDIUM5.3Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Acce...
CVE-2024-50425MEDIUM6.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roland Murg WP Booking Syste...
CVE-2024-50424MEDIUM6.5Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access...
CVE-2024-50423MEDIUM5.4Missing Authorization vulnerability in WPDeveloper Templately templately allows Exploiting Incorrectly Configured Access...
CVE-2024-50422MEDIUM5.3Missing Authorization vulnerability in Cloudways Breeze breeze allows Exploiting Incorrectly Configured Access Control S...
CVE-2024-50421MEDIUM5.3Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-pa...
CVE-2024-48572MEDIUM5.3A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addres...
CVE-2024-48461MEDIUM4.8Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitr...
CVE-2024-10491MEDIUM5.3A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in...
CVE-2024-25566MEDIUM6.1An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect UR...
CVE-2024-50334MEDIUM5.3Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /a...
CVE-2024-49768MEDIUM4.8Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly...
CVE-2024-9505MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-51076MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ...
CVE-2024-51075MEDIUM6.1A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Bo...
CVE-2024-49634MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Mem...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now