2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9206MEDIUM6.1The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use...
CVE-2024-47793MEDIUM5.4Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When acces...
CVE-2024-38820MEDIUM5.3The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() ...
CVE-2024-9892MEDIUM4.8The Add Widget After Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2024-9848MEDIUM5.4The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a...
CVE-2024-9452MEDIUM5.4The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t...
CVE-2024-9383MEDIUM6.1The Parcel Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all ve...
CVE-2024-9382MEDIUM6.1The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parame...
CVE-2024-9373MEDIUM5.4The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t...
CVE-2024-9366MEDIUM5.4The Easy Menu Manager | WPZest plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in...
CVE-2024-9364MEDIUM4.3The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability c...
CVE-2024-9361MEDIUM4.3The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorize...
CVE-2024-9350MEDIUM6.1The DPD Baltic Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_value' para...
CVE-2024-8916MEDIUM5.4The Suki Sites Import plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers...
CVE-2024-8790MEDIUM6.1The Social Share With Floating Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-8740MEDIUM6.1The GetResponse Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-10049MEDIUM6.1The Edit WooCommerce Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ param...
CVE-2024-10040MEDIUM4.3The Infinite-Scroll plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-10014MEDIUM5.4The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode ...
CVE-2024-49023MEDIUM5.3Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-43580MEDIUM5.4Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-7316MEDIUM5.9Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric CNC Series allows a remote unaut...
CVE-2024-27766MEDIUM5.7An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE...
CVE-2024-49288MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VillaTheme Email T...
CVE-2024-49282MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Responsiv...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now