2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49703MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpE...
CVE-2024-49683MEDIUM5.3Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp...
CVE-2024-49682MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allo...
CVE-2024-9650MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all...
CVE-2024-9214MEDIUM6.1The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-10176MEDIUM6.4The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embe...
CVE-2024-8312MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17...
CVE-2024-6826MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17....
CVE-2024-8717MEDIUM6.1The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-10050MEDIUM4.3The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to...
CVE-2024-9943MEDIUM6.3The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross...
CVE-2024-9531MEDIUM4.3The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unaut...
CVE-2024-8667MEDIUM4.3The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ...
CVE-2024-9865MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-9864MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-40595MEDIUM5.3An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise b...
CVE-2024-9374MEDIUM6.1The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_...
CVE-2024-48213MEDIUM4.3RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php.
CVE-2024-40432MEDIUM6.5A lack of input validation in Realtek SD card reader driver before 10.0.26100.21374 through the implementation of the IO...
CVE-2024-9949MEDIUM6.1Denial of Service in Forescout SecureConnector 11.1.02.1019 on Windows allows Unprivileged user to corrupt the configura...
CVE-2024-20526MEDIUM5.3A vulnerability in the SSH server of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, re...
CVE-2024-20493MEDIUM5.3A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Securit...
CVE-2024-20485MEDIUM6.7A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Def...
CVE-2024-20482MEDIUM6.5A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl...
CVE-2024-20481MEDIUM5.8A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco F...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now