2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38670MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Member...
CVE-2024-37960MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Chris Coyie...
CVE-2024-6491MEDIUM4.3The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-6489MEDIUM5.3The Getwid – Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c...
CVE-2024-40347MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Hyland Alfresco Platform 23.2.1-r96 allows attackers to execute ...
CVE-2024-3934MEDIUM6.5The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5....
CVE-2024-6560MEDIUM5.3The Addonify – Quick View For WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up ...
CVE-2024-2337MEDIUM5.4The Easy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'testimonials_g...
CVE-2024-5804MEDIUM4.3The Conditional Fields for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions u...
CVE-2024-41599MEDIUM6.1Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via th...
CVE-2024-41597MEDIUM4.2Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: th...
CVE-2024-41124MEDIUM6.3Puncia is the Official CLI utility for Subdomain Center & Exploit Observer. `API_URLS` is utilizing HTTP instead of HTTP...
CVE-2024-39123MEDIUM5.4In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due...
CVE-2024-29080MEDIUM6.5Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En...
CVE-2024-24970MEDIUM6.5Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application En...
CVE-2024-6908MEDIUM6Improper privilege management in Yugabyte Platform allows authenticated admin users to escalate privileges to SuperAdmin...
CVE-2024-6895MEDIUM6.1Insufficient authentication in user account management in Yugabyte Platform allows local network attackers with a compro...
CVE-2024-0006MEDIUM5.4Information exposure in the logging system in Yugabyte Platform allows local attackers with access to application logs t...
CVE-2024-6916MEDIUM5.5A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a ...
CVE-2024-5977MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Insecure Direct Object Refer...
CVE-2024-6907MEDIUM5.4A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affecte...
CVE-2024-39457MEDIUM5.4Cybozu Garoon 6.0.0 to 6.0.1 contains a cross-site scripting vulnerability in PDF preview. If this vulnerability is expl...
CVE-2024-6799MEDIUM4.3The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to...
CVE-2024-5604MEDIUM5.9The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-21583MEDIUM4.1Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now