2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4602MEDIUM5.4The Embed Peertube Playlist WordPress plugin before 1.10 does not sanitise and escape some of its settings, which could ...
CVE-2024-4272MEDIUM6.1The Support SVG WordPress plugin before 1.1.0 does not sanitize SVG file contents, which enables users with at least th...
CVE-2024-4269MEDIUM6.1The SVG Block WordPress plugin before 1.1.20 does not sanitize SVG file contents, which enables users with at least the ...
CVE-2024-4217MEDIUM4.7The shortcodes-ultimate-pro WordPress plugin before 7.1.5 does not properly escape some of its shortcodes' settings, mak...
CVE-2024-3964MEDIUM5.9The Product Enquiry for WooCommerce WordPress plugin before 3.1.8 does not sanitise and escape some of its settings, whi...
CVE-2024-3963MEDIUM6.5The Giveaways and Contests by RafflePress WordPress plugin before 1.12.14 does not sanitise and escape some parameters,...
CVE-2024-3919MEDIUM4.6The OpenPGP Form Encryption for WordPress plugin before 1.5.1 does not validate and escape some of its shortcode attribu...
CVE-2024-3753MEDIUM5.9The Hostel WordPress plugin before 1.1.5.3 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-3751MEDIUM4.8The Seriously Simple Podcasting WordPress plugin before 3.3.0 does not sanitise and escape some of its settings, which c...
CVE-2024-3710MEDIUM6.8The Image Photo Gallery Final Tiles Grid WordPress plugin before 3.6.0 does not validate and escape some of its shortcod...
CVE-2024-3632MEDIUM6.8The Smart Image Gallery WordPress plugin before 1.0.19 does not have CSRF check in place when updating its settings, whi...
CVE-2024-3026MEDIUM5.4The WordPress Button Plugin MaxButtons WordPress plugin before 9.7.8 does not sanitise and escape some parameters, which...
CVE-2024-2870MEDIUM6.1The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape a parameter before outputting...
CVE-2024-31947MEDIUM6.5StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a c...
CVE-2024-5902MEDIUM6.1The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera...
CVE-2024-40690MEDIUM5.4IBM InfoSphere Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to emb...
CVE-2024-40547MEDIUM6.5PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component ...
CVE-2024-38716MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Cale...
CVE-2024-37405MEDIUM6.5Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) a...
CVE-2024-39916MEDIUM6.4FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the N...
CVE-2024-39909MEDIUM6.5KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container...
CVE-2024-38715MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows P...
CVE-2024-38709MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating...
CVE-2024-38704MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress ...
CVE-2024-38700MEDIUM6.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in real...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now