2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-9851MEDIUM5.4The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers...
CVE-2024-9828MEDIUM4.1The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it...
CVE-2024-9768MEDIUM4.8The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allo...
CVE-2024-9600MEDIUM4.8The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-9542MEDIUM4.3The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-9442MEDIUM5.4The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-9371MEDIUM6.1The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-9111MEDIUM6.4The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi...
CVE-2024-8157MEDIUM4.3The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which...
CVE-2024-7517HIGH7.8A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms...
CVE-2024-5029MEDIUM4.8The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is miss...
CVE-2024-52797HIGH7.5Opencast is free and open source software for automated video capture and distribution. First noticed in Opencast 13 and...
CVE-2024-52067MEDIUM4.9Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context valu...
CVE-2024-45663HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1, 11.5, and 12.1 is vulnerable to a denial of serv...
CVE-2024-30896CRITICAL9.1InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut...
CVE-2024-11596MEDIUM5.5ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or cra...
CVE-2024-11595MEDIUM5.5FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet in...
CVE-2024-11456MEDIUM6.1The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2024-11455MEDIUM6.4The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-ma...
CVE-2024-11447MEDIUM6.1The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-11440MEDIUM6.4The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' sh...
CVE-2024-11438MEDIUM6.4The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '...
CVE-2024-11435MEDIUM6.1The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter...
CVE-2024-11432MEDIUM6.4The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter'...
CVE-2024-11428MEDIUM6.4The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now