2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9798MEDIUM5.3The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for at...
CVE-2024-9780MEDIUM5.5ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file
CVE-2024-9520MEDIUM5.4The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing ...
CVE-2024-9074MEDIUM5.4The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve...
CVE-2024-9067MEDIUM4.3The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-8477MEDIUM4.3The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerab...
CVE-2024-9685MEDIUM4.3The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing c...
CVE-2024-9457MEDIUM5.4The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up...
CVE-2024-9377MEDIUM6.1The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Script...
CVE-2024-9205MEDIUM6.1The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-9072MEDIUM5.4The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-9066MEDIUM5.4The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in ...
CVE-2024-9065MEDIUM5.3The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-9064MEDIUM5.4The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all v...
CVE-2024-9057MEDIUM5.4The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-8987MEDIUM5.4The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress ...
CVE-2024-8729MEDIUM6.1The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add...
CVE-2024-8513MEDIUM5.3The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable...
CVE-2024-7048MEDIUM5.4In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/...
CVE-2024-48942MEDIUM5.9The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to eas...
CVE-2024-48941MEDIUM5.4The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to byp...
CVE-2024-8264MEDIUM5.5Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent...
CVE-2024-48933MEDIUM6.1A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary we...
CVE-2024-7041MEDIUM6.5An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerabili...
CVE-2024-38818MEDIUM6.7VMware NSX contains a local privilege escalation vulnerability.  An authenticated malicious actor may exploit this vuln...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now