2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3184MEDIUM5.9Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when comp...
CVE-2024-9213MEDIUM6.1The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-9352MEDIUM4.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site...
CVE-2024-9351MEDIUM4.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site...
CVE-2024-9347MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-8719MEDIUM6.1The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like...
CVE-2024-7417MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t...
CVE-2024-49593MEDIUM5.3In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the ...
CVE-2024-9940MEDIUM4.3The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5....
CVE-2024-9240MEDIUM6.1The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-45767MEDIUM6.5Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used...
CVE-2024-48758MEDIUM6.1dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the addPro parameter of the compone...
CVE-2024-47889MEDIUM6.6Action Mailer is a framework for designing email service layers. Starting in version 3.0.0 and prior to versions 6.1.7.9...
CVE-2024-47888MEDIUM6.6Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0....
CVE-2024-46212MEDIUM4.9An issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory tr...
CVE-2024-44762MEDIUM5.3A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid ...
CVE-2024-47887MEDIUM6.6Action Pack is a framework for handling and responding to web requests. Starting in version 4.0.0 and prior to versions ...
CVE-2024-47836MEDIUM4.3Admidio is an open-source user management solution. Prior to version 4.3.12, an unsafe deserialization vulnerability all...
CVE-2024-45796MEDIUM5.3Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-41128MEDIUM6.6Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions ...
CVE-2024-9143MEDIUM4.3Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial ...
CVE-2024-46606MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to ...
CVE-2024-46605MEDIUM6.1A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to ...
CVE-2024-45072MEDIUM5.5IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process...
CVE-2024-45071MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now