2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-44821MEDIUM5.3ZZCMS 2023 contains a vulnerability in the captcha reuse logic located in /inc/function.php. The checkyzm function does ...
CVE-2024-44818MEDIUM5.4Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information v...
CVE-2024-8411MEDIUM4.3A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_int...
CVE-2024-7077MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Semtek Informatics...
CVE-2024-44820MEDIUM6.1A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at...
CVE-2024-44819MEDIUM6.1Cross Site Scripting vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information v...
CVE-2024-8407MEDIUM5.4A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as p...
CVE-2024-44383MEDIUM6.8WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
CVE-2024-8413MEDIUM6.1Cross Site Scripting (XSS) vulnerability through the action parameter in index.php. Affected product codebase https://g...
CVE-2024-8318MEDIUM5.4The Attributes for Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributesForBlocks...
CVE-2024-8123MEDIUM5.4The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Insecure Direct Object Reference ...
CVE-2024-8121MEDIUM4.3The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of user...
CVE-2024-8119MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-8117MEDIUM6.1The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting vi...
CVE-2024-8106MEDIUM6.5The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Sensitive Information Exposure in...
CVE-2024-8104MEDIUM6.5The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versio...
CVE-2024-8325MEDIUM5.4The Blockspare: Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites – Post Grids, Sliders, Carousels, Count...
CVE-2024-7786MEDIUM5.3The Sensei LMS WordPress plugin before 4.24.2 does not properly protect some its REST API routes, allowing unauthentica...
CVE-2024-6889MEDIUM4.8The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o...
CVE-2024-6888MEDIUM4.8The Secure Copy Content Protection and Content Locking WordPress plugin before 4.1.7 does not sanitise and escape some o...
CVE-2024-6722MEDIUM4.8The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and e...
CVE-2024-6020MEDIUM6.1The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_...
CVE-2024-34661MEDIUM4.3Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to ...
CVE-2024-34659MEDIUM5.3Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victi...
CVE-2024-34655MEDIUM5.5Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now