2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31971MEDIUM4.8Multiple stored cross-site scripting (XSS) vulnerabilities on AdTran NetVanta 3120 18.01.01.00.E devices allow remote at...
CVE-2024-5818MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored DOM-based Cross-Site Scripting via...
CVE-2024-3896MEDIUM5.4The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-6896MEDIUM5.4The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File...
CVE-2024-7065MEDIUM4.3A vulnerability was found in Spina CMS up to 2.18.0. It has been classified as problematic. Affected is an unknown funct...
CVE-2024-6930MEDIUM5.4The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute withi...
CVE-2024-6874MEDIUM4.3libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to...
CVE-2024-3297MEDIUM6.5An issue in the Certificate Authenticated Session Establishment (CASE) protocol for establishing secure sessions between...
CVE-2024-6629MEDIUM5.4The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video sh...
CVE-2024-6571MEDIUM5.3The Optimize Images ALT Text (alt tag) & names for SEO using AI plugin for WordPress is vulnerable to Full Path Disclosu...
CVE-2024-6553MEDIUM5.3The WP Meteor Website Speed Optimization Addon plugin for WordPress is vulnerable to Full Path Disclosure in all version...
CVE-2024-6836MEDIUM4.3The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps ...
CVE-2024-6094MEDIUM4.8The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high pr...
CVE-2024-40767MEDIUM6.5In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actuall...
CVE-2024-5861MEDIUM6.5The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a mi...
CVE-2024-3246MEDIUM5.4The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin...
CVE-2024-6755MEDIUM5.3The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing...
CVE-2024-6754MEDIUM4.3The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability c...
CVE-2024-6753MEDIUM6.1The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in...
CVE-2024-6752MEDIUM5.4The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in ...
CVE-2024-6751MEDIUM6.5The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including...
CVE-2024-41656MEDIUM5.4Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1,...
CVE-2024-41665MEDIUM5.4Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnera...
CVE-2024-41664MEDIUM5.4Canarytokens help track activity and actions on a network. Prior to `sha-8ea5315`, Canarytokens.org was vulnerable to a ...
CVE-2024-39702MEDIUM5.9In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now