2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-20414MEDIUM6.5A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, re...
CVE-2024-7421MEDIUM5.5An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers ...
CVE-2024-46600MEDIUM4.7dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.p...
CVE-2024-46485MEDIUM6.3dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate
CVE-2024-43990MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affe...
CVE-2024-43237MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag...
CVE-2024-30128MEDIUM6.5HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask thei...
CVE-2024-6512MEDIUM6.5Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows aut...
CVE-2024-45613MEDIUM6.1CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Script...
CVE-2024-8546MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Vide...
CVE-2024-8858MEDIUM5.4The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_set...
CVE-2024-9169MEDIUM4.8The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all v...
CVE-2024-47303MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh ...
CVE-2024-40761MEDIUM5.3Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using ...
CVE-2024-23454MEDIUM6.2Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be pres...
CVE-2024-8910MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ...
CVE-2024-8678MEDIUM5.3The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mis...
CVE-2024-3866MEDIUM6.1The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Re...
CVE-2024-8658MEDIUM5.3The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, Woo...
CVE-2024-7892MEDIUM4.3The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which cou...
CVE-2024-7878MEDIUM4.8The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-6845MEDIUM5.3The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, a...
CVE-2024-8668MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-8516MEDIUM4.3The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an...
CVE-2024-8515MEDIUM5.4The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widget...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now