2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-46081MEDIUM5.4Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS). An authenticated user can craft malicious p...
CVE-2024-46079MEDIUM6.1Scriptcase v9.10.023 and before is vulnerable to Cross Site Scripting (XSS) in proj_new.php via the Descricao parameter.
CVE-2024-31835MEDIUM4.8Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code vi...
CVE-2024-9398MEDIUM5.3By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if...
CVE-2024-9397MEDIUM6.1A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permiss...
CVE-2024-9395MEDIUM5.3A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in th...
CVE-2024-9391MEDIUM6.5A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full scr...
CVE-2024-47604MEDIUM6.1NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handli...
CVE-2024-47071MEDIUM6.8OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authent...
CVE-2024-45967MEDIUM4.7Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) in index.php/admin/site/widget.
CVE-2024-45408MEDIUM6.5eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that c...
CVE-2024-44610MEDIUM5.6PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via sh...
CVE-2024-25658MEDIUM6.5Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (w...
CVE-2024-44744MEDIUM5.7An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted bina...
CVE-2024-9405MEDIUM5.3An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting v...
CVE-2024-9118MEDIUM6.4The QS Dark Mode Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ve...
CVE-2024-9060MEDIUM6.4The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versio...
CVE-2024-9241MEDIUM6.1The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-9228MEDIUM6.1The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...
CVE-2024-9224MEDIUM6.5The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1...
CVE-2024-9220MEDIUM6.1The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_...
CVE-2024-9209MEDIUM6.1The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query...
CVE-2024-8799MEDIUM6.1The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8793MEDIUM6.1The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress...
CVE-2024-8786MEDIUM6.1The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now