2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45124MEDIUM5.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45123MEDIUM6.1Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a reflected Cross-Site Scrip...
CVE-2024-45122MEDIUM4.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45121MEDIUM4.3Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-45119MEDIUM4.9Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 (and earlier) are affected by a Server-Side Request Forg...
CVE-2024-45118MEDIUM6.5Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control v...
CVE-2024-22068MEDIUM6.5Improper Privilege Management vulnerability in ZTE ZXR10 1800-2S series ,ZXR10 2800-4,ZXR10 3800-8,ZXR10 160 series on 6...
CVE-2024-9802MEDIUM5.3The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The respons...
CVE-2024-9798MEDIUM5.3The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at...
CVE-2024-7049MEDIUM5.4In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending ...
CVE-2024-9780MEDIUM5.5ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
CVE-2024-9520MEDIUM5.4The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ...
CVE-2024-9074MEDIUM5.4The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve...
CVE-2024-9067MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-8477MEDIUM4.3The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab...
CVE-2024-9685MEDIUM4.3The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c...
CVE-2024-9457MEDIUM5.4The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up...
CVE-2024-9377MEDIUM6.1The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-9205MEDIUM6.1The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-9072MEDIUM5.4The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-9066MEDIUM5.4The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ...
CVE-2024-9065MEDIUM5.3The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-9064MEDIUM5.4The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v...
CVE-2024-9057MEDIUM5.4The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-8987MEDIUM5.4The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now