2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12219MEDIUM6.1The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2024-11999HIGH8.8CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the devic...
CVE-2024-9624HIGH7.6The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and inclu...
CVE-2024-54125LOW3.3Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 ...
CVE-2024-38499HIGH8.8CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This woul...
CVE-2024-55864MEDIUM4.8Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious...
CVE-2024-12356CRITICAL9.8A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which ca...
CVE-2024-12239MEDIUM6.1The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navig...
CVE-2024-10205CRITICAL9.4Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail ...
CVE-2024-11906MEDIUM6.4The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' sho...
CVE-2024-11905MEDIUM6.4The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte...
CVE-2024-11902MEDIUM6.4The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations...
CVE-2024-11900MEDIUM6.4The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-56017HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects...
CVE-2024-55452MEDIUM5.4A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of ...
CVE-2024-55451MEDIUM4.8A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in U...
CVE-2024-55085CRITICAL9.8GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background managem...
CVE-2024-35230MEDIUM5.3GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. In affe...
CVE-2024-12443MEDIUM6.4The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Sto...
CVE-2024-55554MEDIUM5.4Intrexx Portal Server before 12.0.2 allows XSS via a user-defined portlet.
CVE-2024-52949HIGH7.5iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control th...
CVE-2024-37776MEDIUM4.8A cross-site scripting (XSS) vulnerability in Sunbird DCIM dcTrack v9.1.2 allows attackers to execute arbitrary web scri...
CVE-2024-37775HIGH7.5Incorrect access control in Sunbird DCIM dcTrack v9.1.2 allows attackers to create or update a ticket with a location wh...
CVE-2024-37774HIGH8A Cross-Site Request Forgery (CSRF) in Sunbird DCIM dcTrack v9.1.2 allows authenticated attackers to escalate their priv...
CVE-2024-37773MEDIUM4.8An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now