2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12594HIGH8.8The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora...
CVE-2024-12405MEDIUM6.1The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in ...
CVE-2024-12210MEDIUM4.3The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-12100MEDIUM6.1The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-12096MEDIUM6.1The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it b...
CVE-2024-12034MEDIUM5.3The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, ...
CVE-2024-11885MEDIUM6.4The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte...
CVE-2024-12710MEDIUM6.1The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi...
CVE-2024-12617MEDIUM5.4The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c...
CVE-2024-12518MEDIUM6.4The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho...
CVE-2024-12507MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2024-12266MEDIUM6.5The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due...
CVE-2024-9427MEDIUM5.4A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link ...
CVE-2024-47515HIGH8.1A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di...
CVE-2024-12582HIGH7.1A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metri...
CVE-2024-53961HIGH8.1ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di...
CVE-2024-56363HIGH7.8APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo...
CVE-2024-56362MEDIUM5.5Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext...
CVE-2024-53276MEDIUM6.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a...
CVE-2024-53275MEDIUM5.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, t...
CVE-2024-40896CRITICAL9.1In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for externa...
CVE-2024-56364MEDIUM5.4SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, w...
CVE-2024-56326HIGH7.8Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects ca...
CVE-2024-56201HIGH8.8Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allo...
CVE-2024-55947HIGH8.8Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the ser...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now