2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-46327MEDIUM5.7An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a dir...
CVE-2024-31899MEDIUM4.3IBM Cognos Command Center 10.2.4.1 and 10.2.5 could disclose highly sensitive user information to an authenticated user ...
CVE-2024-8633MEDIUM4.8The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ...
CVE-2024-8725MEDIUM5.4Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a...
CVE-2024-9198MEDIUM5.4Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored X...
CVE-2024-9173MEDIUM5.4The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-9127MEDIUM5.4The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter i...
CVE-2024-9125MEDIUM5.4The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to...
CVE-2024-9117MEDIUM5.4The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...
CVE-2024-9115MEDIUM5.4The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-9025MEDIUM5.3The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2024-8872MEDIUM6.1The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-47337MEDIUM4.3Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: fr...
CVE-2024-47044MEDIUM5.3Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to...
CVE-2024-8861MEDIUM5.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-47145MEDIUM4.3Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels...
CVE-2024-47003MEDIUM6.5Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a str...
CVE-2024-45843MEDIUM5.4Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denyli...
CVE-2024-42406MEDIUM5.4Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize req...
CVE-2024-6517MEDIUM6.1The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputtin...
CVE-2024-45836MEDIUM6.1Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logg...
CVE-2024-45372MEDIUM6.5MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious pa...
CVE-2024-8803MEDIUM6.1The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ...
CVE-2024-8723MEDIUM5.4The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in al...
CVE-2024-8552MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now