2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8337MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VC...
CVE-2024-8274MEDIUM6.1The WP Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters from...
CVE-2024-7858MEDIUM6.3The Media Library Folders plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on ...
CVE-2024-7122MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in a...
CVE-2024-8319MEDIUM4.3The Tourfic plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.11....
CVE-2024-44944MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: use helper function to calcul...
CVE-2024-42412MEDIUM6.1Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in...
CVE-2024-34577MEDIUM6.1Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to ...
CVE-2024-5879MEDIUM5.4The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-3998MEDIUM5.4The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in a...
CVE-2024-5061MEDIUM5.4The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wr...
CVE-2024-5024MEDIUM6.1The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr...
CVE-2024-4401MEDIUM5.4The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_sli...
CVE-2024-8328MEDIUM5.4Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific pa...
CVE-2024-1543MEDIUM5.5The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacke...
CVE-2024-41349MEDIUM6.1unmark 1.9.2 is vulnerable to Cross Site Scripting (XSS) via application/views/marks/add_by_url.php.
CVE-2024-41371MEDIUM6.1Organizr v1.90 is vulnerable to Cross Site Scripting (XSS) via api.php.
CVE-2024-41358MEDIUM6.1phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
CVE-2024-41351MEDIUM6.1bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/getContent.php
CVE-2024-41350MEDIUM6.1bjyadmin commit a560fd5 is vulnerable to Cross Site Scripting (XSS) via Public/statics/umeditor1_2_3/php/imageUp.php
CVE-2024-41348MEDIUM6.1openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/alsearch.php
CVE-2024-41347MEDIUM6.1openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/settings.php
CVE-2024-41346MEDIUM5.4openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/submit.php
CVE-2024-41345MEDIUM5.4openflights commit 5234b5b is vulnerable to Cross-Site Scripting (XSS) via php/trip.php
CVE-2024-34018MEDIUM5.5Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap D...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now