2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8282MEDIUM5.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’...
CVE-2024-9378MEDIUM6.1The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter ...
CVE-2024-9344MEDIUM6.1The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaSc...
CVE-2024-9218MEDIUM6.1The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plu...
CVE-2024-9225MEDIUM6.1The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-9222MEDIUM6.1The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres...
CVE-2024-9210MEDIUM6.1The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_...
CVE-2024-9172MEDIUM5.4The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-8967MEDIUM5.4The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-8800MEDIUM6.1The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and m...
CVE-2024-8254MEDIUM6.3The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin f...
CVE-2024-9333MEDIUM5.3Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited am...
CVE-2024-9174MEDIUM5.4Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
CVE-2024-21530MEDIUM4.5Versions of the package cocoon before 0.4.0 are vulnerable to Reusing a Nonce, Key Pair in Encryption when the encrypt, ...
CVE-2024-9407MEDIUM4.7A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not pro...
CVE-2024-47609MEDIUM6.9Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server ther...
CVE-2024-47528MEDIUM4.8LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. Stored Cross-Site Scripting (XSS) can be ach...
CVE-2024-47527MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-47525MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-47524MEDIUM4.8LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Gro...
CVE-2024-47523MEDIUM5.4LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerab...
CVE-2024-46082MEDIUM5.4Scriptcase v.9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in nm_cor.php via the form and field parame...
CVE-2024-9411MEDIUM5.3A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admi...
CVE-2024-9355MEDIUM6.5A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized b...
CVE-2024-46083MEDIUM5.4Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now