2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-45353MEDIUM4.3An intent redriction vulnerability exists in the Xiaomi quick App framework application product. The vulnerability is ca...
CVE-2024-55965MEDIUM6.5An issue was discovered in Appsmith before 1.51. Users invited as "App Viewer" incorrectly have access to development in...
CVE-2024-55963MEDIUM6.5An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the ...
CVE-2024-41643MEDIUM6.8An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell log...
CVE-2024-13411MEDIUM6.4The Zapier for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and in...
CVE-2024-13702MEDIUM5.4The CRM and Lead Management by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
CVE-2024-30155MEDIUM4.3HCL SX does not set the secure attribute on authorization tokens or session cookies. Attackers may potentially be able t...
CVE-2024-11847MEDIUM4.8The wp-svg-upload WordPress plugin through 1.0.0 does not sanitize SVG file contents, which enables users with at least ...
CVE-2024-55029MEDIUM6.1NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.
CVE-2024-55604MEDIUM4.3Appsmith is a platform to build admin panels, internal tools, and dashboards. Users invited as "App Viewer" should not h...
CVE-2024-11499MEDIUM6.9A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and auth...
CVE-2024-10037MEDIUM5.9A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU applicati...
CVE-2024-53679MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the ...
CVE-2024-13731MEDIUM6.4The Alert Box Block – Display notice/alerts in the front end. plugin for WordPress is vulnerable to Stored Cross-Site Sc...
CVE-2024-13710MEDIUM4.3The Estatebud – Properties & Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u...
CVE-2024-12623MEDIUM6.4The DICOM Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dcm' shortcode in ...
CVE-2024-9770MEDIUM4.7The WP-Recall WordPress plugin before 16.26.12 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2024-13118MEDIUM4.3The IP Based Login WordPress plugin before 2.4.1 does not have CSRF checks in some places, which could allow attackers t...
CVE-2024-12682MEDIUM6.1The Smart Maintenance Mode WordPress plugin before 1.5.2 does not sanitise and escape some of its settings, which could ...
CVE-2024-12109MEDIUM4.1The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter ...
CVE-2024-11503MEDIUM6.1The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-11273MEDIUM6.1The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s...
CVE-2024-11272MEDIUM6.1The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s...
CVE-2024-10703MEDIUM6.1The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its setti...
CVE-2024-10679MEDIUM6.1The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now