2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-44919MEDIUM5.4A cross-site scripting (XSS) vulnerability in the component admin_ads.php of SeaCMS v12.9 allows attackers to execute ar...
CVE-2024-43954MEDIUM6.3Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not Properly Constrained by ACLs.T...
CVE-2024-35118MEDIUM4.6IBM MaaS360 for Android 6.31 through 8.60 is using hard coded credentials that can be obtained by a user with physical a...
CVE-2024-8304MEDIUM4.9A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an un...
CVE-2024-8303MEDIUM6.3A vulnerability classified as critical has been found in dingfanzu CMS up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. T...
CVE-2024-43940MEDIUM6.5Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr...
CVE-2024-43939MEDIUM6.5Missing Authorization vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Accessing Functionality Not Properly Constr...
CVE-2024-1056MEDIUM5.4The FunnelKit Funnel Builder Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'allow_iframe...
CVE-2024-1384MEDIUM5.4The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-7895MEDIUM5.4The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘t...
CVE-2024-7606MEDIUM5.4The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' sho...
CVE-2024-7418MEDIUM4.3The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to ...
CVE-2024-7132MEDIUM4.8The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of i...
CVE-2024-6927MEDIUM4.8The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-6551MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Full Path Disclosure in all ...
CVE-2024-5987MEDIUM4.3The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2024-5857MEDIUM5.3The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress...
CVE-2024-5624MEDIUM6.1Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based a...
CVE-2024-5417MEDIUM5.4The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting the...
CVE-2024-45440MEDIUM5.3core/authorize.php in Drupal 11.x-dev allows Full Path Disclosure (even when error logging is None) if the value of hash...
CVE-2024-43986MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople ...
CVE-2024-3944MEDIUM4.8The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and in...
CVE-2024-38304MEDIUM6.5Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of B...
CVE-2024-38303MEDIUM6Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability....
CVE-2024-7857MEDIUM6.5The Media Library Folders plugin for WordPress is vulnerable to second order SQL Injection via the 'sort_type' parameter...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now