2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9898MEDIUM5.4The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc...
CVE-2024-45713MEDIUM4.4SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been...
CVE-2024-8920MEDIUM6.4The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2024-49392MEDIUM4.8Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro...
CVE-2024-49386MEDIUM5.7Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows...
CVE-2024-9951MEDIUM6.1The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete...
CVE-2024-3187MEDIUM5.9This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6....
CVE-2024-3186MEDIUM5.3CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when ...
CVE-2024-3184MEDIUM5.9Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when comp...
CVE-2024-9213MEDIUM6.1The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-9352MEDIUM4.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site...
CVE-2024-9351MEDIUM4.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site...
CVE-2024-9347MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-8719MEDIUM6.1The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like...
CVE-2024-7417MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t...
CVE-2024-49593MEDIUM5.3In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the ...
CVE-2024-9940MEDIUM4.3The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5....
CVE-2024-9240MEDIUM6.1The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-45767MEDIUM6.5Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used...
CVE-2024-48758MEDIUM6.1dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the compone...
CVE-2024-47889MEDIUM6.6Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9...
CVE-2024-47888MEDIUM6.6Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0....
CVE-2024-46212MEDIUM4.9An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory tr...
CVE-2024-44762MEDIUM5.3A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid ...
CVE-2024-47887MEDIUM6.6Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now