2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7386MEDIUM4.3The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery i...
CVE-2024-6590MEDIUM4.3The Spreadsheet Integration – Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Disp...
CVE-2024-9148MEDIUM6.1Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed...
CVE-2024-9141MEDIUM5.4Cross-Site Scripting (XSS) vulnerability in the Oct8ne system. This flaw could allow an attacker to embed harmful JavaSc...
CVE-2024-8941MEDIUM5.3Path traversal vulnerability in Scriptcase version 9.4.019, in /scriptcase/devel/compat/nm_edit_php_edit.php (in the “su...
CVE-2024-8919MEDIUM5.4The Confetti Fall Animation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'confetti...
CVE-2024-8917MEDIUM5.4The AnWP Football Leagues plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-8801MEDIUM4.3The Happy Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t...
CVE-2024-8437MEDIUM4.3The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to unauthorized access due to a missin...
CVE-2024-8291MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A ...
CVE-2024-8267MEDIUM5.4The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable ...
CVE-2024-8103MEDIUM5.4The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in ...
CVE-2024-8067MEDIUM5.8In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument inject...
CVE-2024-7398MEDIUM5.4Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addit...
CVE-2024-47048MEDIUM5.4Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release no...
CVE-2024-46934MEDIUM6.1Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XS...
CVE-2024-41725MEDIUM6.1ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may ...
CVE-2024-38324MEDIUM6.5IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registrati...
CVE-2024-8794MEDIUM5.3The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi...
CVE-2024-8628MEDIUM5.4The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable ...
CVE-2024-8738MEDIUM6.1The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-8716MEDIUM6.1The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-8662MEDIUM6.1The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8657MEDIUM5.4The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc...
CVE-2024-8544MEDIUM6.1The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now