2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-39875MEDIUM4.3A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application ...
CVE-2024-39871MEDIUM5.4A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected applications do ...
CVE-2024-39869MEDIUM6.5A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). Affected products allow t...
CVE-2024-37996MEDIUM4.8A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (A...
CVE-2024-37499MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & S...
CVE-2024-37464MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPZOOM Beaver Builder Ad...
CVE-2024-5946MEDIUM6.4The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ta...
CVE-2024-5632MEDIUM5.3Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, create a WiFi network ...
CVE-2024-5631MEDIUM6Longse NVR (Network Video Recorder) model NVR3608PGE2W, as well as products based on this device, are transmitting user'...
CVE-2024-4862MEDIUM5.4The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via sever...
CVE-2024-37442MEDIUM5.5Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Phot...
CVE-2024-37437MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...
CVE-2024-37430MEDIUM5.3Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon ...
CVE-2024-37224MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in smartypants SP Project &...
CVE-2024-6168MEDIUM4.3The Just Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-6167MEDIUM4.3The Just Custom Fields plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capab...
CVE-2024-5993MEDIUM5.4The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-5992MEDIUM6.5The Cliengo – Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-5937MEDIUM6.4The Simple Alert Boxes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Alert shortcod...
CVE-2024-5856MEDIUM4.3The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability ...
CVE-2024-5810MEDIUM5.3The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access...
CVE-2024-5704MEDIUM4.3The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthori...
CVE-2024-5669MEDIUM6.4The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin for WordPress is vulnerable to unauthor...
CVE-2024-5648MEDIUM5.4The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-5600MEDIUM5.4The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Sit...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now