2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22034MEDIUM5.5Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker t...
CVE-2024-22033MEDIUM6.3The OBS service obs-service-download_url was vulnerable to a command injection vulnerability. The attacker could provide...
CVE-2024-6380MEDIUM5.4A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEX...
CVE-2024-8921MEDIUM6.4The Zita Elementor Site Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-9444MEDIUM5.4The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File up...
CVE-2024-9540MEDIUM4.3The Sina Extension for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-45715MEDIUM5.2The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to exis...
CVE-2024-45714MEDIUM4.1Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a v...
CVE-2024-45461MEDIUM6.3The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources,...
CVE-2024-9582MEDIUM5.4The Accordion Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘html’ attribute of an ac...
CVE-2024-8918MEDIUM5.4The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and inc...
CVE-2024-9937MEDIUM6.1The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' paramete...
CVE-2024-9888MEDIUM5.4The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-9873MEDIUM5.4The Community by PeepSo – Social Network, Membership, Registration, User Profiles, Premium – Mobile App plugin for WordP...
CVE-2024-9891MEDIUM4.3The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due...
CVE-2024-9652MEDIUM6.1The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all...
CVE-2024-9649MEDIUM4.3The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request For...
CVE-2024-9647MEDIUM6.1The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all version...
CVE-2024-9521MEDIUM6.4The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and i...
CVE-2024-9104MEDIUM5.6The UltimateAI plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.8.3. ...
CVE-2024-8787MEDIUM6.1The Smart Online Order for Clover plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
CVE-2024-8541MEDIUM6.1The Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons plugin fo...
CVE-2024-38204MEDIUM6.5Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
CVE-2024-9966MEDIUM5.3Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass ...
CVE-2024-9964MEDIUM4.3Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now