2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5457MEDIUM5.4The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions...
CVE-2024-4868MEDIUM5.4The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Event...
CVE-2024-4102MEDIUM5.4The Pricing Table plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on...
CVE-2024-4100MEDIUM5.3The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2024-3608MEDIUM5.3The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check o...
CVE-2024-3603MEDIUM5.4The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' sho...
CVE-2024-3563MEDIUM5.4The Genesis Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sharing block in a...
CVE-2024-3228MEDIUM5.3The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-5881MEDIUM6.4The Webico Slider Flatsome Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wbc...
CVE-2024-37923MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.T...
CVE-2024-6334MEDIUM6.1The Easy Table of Contents WordPress plugin before 2.0.67.1 does not sanitise and escape some of its settings, which cou...
CVE-2024-5802MEDIUM4.8The URL Shortener by Myhop WordPress plugin through 1.0.17 does not sanitise and escape some of its settings, which coul...
CVE-2024-3410MEDIUM4.3The DN Footer Contacts WordPress plugin before 1.6.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-6171MEDIUM5.3The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address ...
CVE-2024-6170MEDIUM5.4The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-6169MEDIUM5.4The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-4667MEDIUM5.4The Blog, Posts and Category Filter for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-39600MEDIUM4.2Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which...
CVE-2024-39599MEDIUM4.7Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can by...
CVE-2024-39596MEDIUM4.3Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which ...
CVE-2024-39595MEDIUM5.4SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user-controlled input...
CVE-2024-39594MEDIUM6.1SAP Business Warehouse - Business Planning and Simulation application does not sufficiently encode user controlled input...
CVE-2024-37180MEDIUM5.3Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote...
CVE-2024-37175MEDIUM6.5SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of p...
CVE-2024-37172MEDIUM5.4SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated us...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now