2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-50516MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in adamskaat Countdow...
CVE-2024-50515MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja...
CVE-2024-50514MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kevin Stover Ninja...
CVE-2024-50513MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPXPO PostX ultima...
CVE-2024-50417HIGH8.8Missing Authorization vulnerability in boldthemes Bold Page Builder bold-page-builder allows Exploiting Incorrectly Conf...
CVE-2024-49697MEDIUM4.3Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incor...
CVE-2024-49689MEDIUM5.4Missing Authorization vulnerability in Harmonic Design HD Quiz – Save Results Light hd-quiz-save-results-light allows Ex...
CVE-2024-49680MEDIUM4.3Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2024-48071MEDIUM6.5E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server direct...
CVE-2024-43338MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Automattic Crowdsignal Dashboard – Polls, Surveys & more polldaddy al...
CVE-2024-52582MEDIUM4.7Cachi2 is a command-line interface tool that pre-fetches a project's dependencies to aid in making the project's build p...
CVE-2024-50803MEDIUM5.4The mediapool feature of the Redaxo Core CMS application v 5.17.1 is vulnerable to Cross Site Scripting(XSS) which allow...
CVE-2024-10524MEDIUM6.5Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the U...
CVE-2024-52711MEDIUM5.7DI-8100 v16.07.26A1 is vulnerable to Buffer Overflow In the ip_position_asp function via the ip parameter.
CVE-2024-11075HIGH8.8A vulnerability in the Incoming Goods Suite allows a user with unprivileged access to the underlying system (e.g. local ...
CVE-2024-10204HIGH7.8Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in...
CVE-2024-9830MEDIUM6.1The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without app...
CVE-2024-9777MEDIUM6.1The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without app...
CVE-2024-52675CRITICAL9.8SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.
CVE-2024-11224MEDIUM6.4The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all...
CVE-2024-11198MEDIUM6.4The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter i...
CVE-2024-11194HIGH8.8The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-11195MEDIUM6.4The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_em...
CVE-2024-11038HIGH7.3The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress...
CVE-2024-11036CRITICAL9.8The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for Wo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now