2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35139MEDIUM5.5IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information fr...
CVE-2024-35137MEDIUM6.2IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to possibly elevate their privileg...
CVE-2024-3801MEDIUM6.1Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in one of GET h...
CVE-2024-3800MEDIUM6.1Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to Reflected XSS via including scripts in requested fi...
CVE-2024-37741MEDIUM5.4OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture.
CVE-2024-5737MEDIUM6.1Script afGdStream.php in AdmirorFrames Joomla! extension doesn’t specify a content type and as a result default (text/ht...
CVE-2024-5925MEDIUM6.4The Theron Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them...
CVE-2024-5922MEDIUM6.4The Scylla lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the them...
CVE-2024-5662MEDIUM6.4The Ultimate Post Kit Addons For Elementor – (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline,...
CVE-2024-5424MEDIUM6.4The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2024-6288MEDIUM4.7The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress...
CVE-2024-5796MEDIUM6.4The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all ver...
CVE-2024-5788MEDIUM6.4The Silesia theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ attribute within the theme's...
CVE-2024-39347MEDIUM5.9Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227...
CVE-2024-2795MEDIUM5.3The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2...
CVE-2024-5730MEDIUM6.1The Pagerank tools WordPress plugin through 1.1.5 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-5729MEDIUM6.1The Simple AL Slider WordPress plugin through 1.2.10 does not sanitise and escape a parameter before outputting it back ...
CVE-2024-5728MEDIUM5.4The Animated AL List WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back i...
CVE-2024-5727MEDIUM4.7The Widget4Call WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-5570MEDIUM6.5The Simple Photoswipe WordPress plugin through 0.1 does not have authorisation check when updating its settings, which c...
CVE-2024-39352MEDIUM4.9A vulnerability regarding incorrect authorization is found in the firmware upgrade functionality. This allows remote aut...
CVE-2024-30109MEDIUM6.1HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multipl...
CVE-2024-6296MEDIUM6.4The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-5864MEDIUM4.3The Easy Affiliate Links plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-5863MEDIUM5.4The Easy Image Collage plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now