2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10638MEDIUM4.1The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter...
CVE-2024-10566MEDIUM6.1The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10565MEDIUM6.1The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10472MEDIUM5.9The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could al...
CVE-2024-10105MEDIUM5.9The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-8315MEDIUM6.8An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may ...
CVE-2024-8314MEDIUM5.5An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in ...
CVE-2024-10208MEDIUM5.1An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <...
CVE-2024-10207MEDIUM5.3A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticat...
CVE-2024-10206MEDIUM6.9A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthentic...
CVE-2024-9103MEDIUM6.1Improper Neutralization of Script in Attributes in a Web Page vulnerability in Forcepoint Email Security (Blocked Messag...
CVE-2024-55279MEDIUM6Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.
CVE-2024-13666MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2024-13856MEDIUM6.4The Your Friendly Drag and Drop Page Builder — Make Builder plugin for WordPress is vulnerable to Server-Side Request Fo...
CVE-2024-13768MEDIUM4.3The CITS Support svg, webp Media and TTF,OTF File Upload, Use Custom Fonts plugin for WordPress is vulnerable to Cross-S...
CVE-2024-13739MEDIUM6.1The Newsletters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "to" parameter in all versi...
CVE-2024-13737MEDIUM4.3The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data d...
CVE-2024-50053MEDIUM5.4Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below...
CVE-2024-54564MEDIUM6.5This issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonom...
CVE-2024-48591MEDIUM6.1Inflectra SpiraTeam 7.2.00 is vulnerable to Cross Site Scripting (XSS). A specially crafted SVG file can be uploaded tha...
CVE-2024-13923MEDIUM6.5The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all...
CVE-2024-13922MEDIUM6.5The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to ins...
CVE-2024-13920MEDIUM4.9The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all version...
CVE-2024-13558MEDIUM5.3The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versi...
CVE-2024-9900MEDIUM6.1mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vuln...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now