2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-52283MEDIUM5.7Missing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a ...
CVE-2024-49503MEDIUM4.6A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE mana...
CVE-2024-49502MEDIUM4.6A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup...
CVE-2024-22038HIGH7.3Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information o...
CVE-2024-22037MEDIUM5.7The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permissio...
CVE-2024-11599MEDIUM5.3Mattermost versions 10.0.x <= 10.0.1, 10.1.x <= 10.1.1, 9.11.x <= 9.11.3, 9.5.x <= 9.5.11 fail to properly validate emai...
CVE-2024-11103CRITICAL9.8The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up t...
CVE-2024-11082CRITICAL9.9The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2024-10798MEDIUM4.3The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up t...
CVE-2024-10780MEDIUM4.3The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up ...
CVE-2024-10670MEDIUM4.3The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and in...
CVE-2024-9669HIGH7.2The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up...
CVE-2024-8066HIGH8.8The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation i...
CVE-2024-11788MEDIUM6.4The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11786MEDIUM6.4The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c...
CVE-2024-11761MEDIUM6.4The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' s...
CVE-2024-11685MEDIUM6.1The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-11684MEDIUM6.1The Kudos Donations – Easy donations and payments with Mollie plugin for WordPress is vulnerable to Reflected Cross-Site...
CVE-2024-11458MEDIUM6.1The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter...
CVE-2024-11431MEDIUM6.4The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode...
CVE-2024-11366MEDIUM6.1The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of ad...
CVE-2024-11333MEDIUM6.4The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode...
CVE-2024-11203MEDIUM5.4The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps i...
CVE-2024-36466HIGH8.8A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin p...
CVE-2024-11925CRITICAL9.8The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and includi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now