2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38394MEDIUM4.3Mismatches in interpreting USB authorization policy between GNOME Settings Daemon (GSD) through 46.0 and the Linux kerne...
CVE-2024-5611MEDIUM6.4The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘label_years’ ...
CVE-2024-5858MEDIUM4.3The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi...
CVE-2024-4095MEDIUM6.4The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'ex...
CVE-2024-2695MEDIUM5.4The Shariff Wrapper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shariff' shortco...
CVE-2024-1399MEDIUM6.4The Restaurant Menu – Food Ordering System – Table Reservation plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-5868MEDIUM5.3The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and inclu...
CVE-2024-5263MEDIUM5.4The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and T...
CVE-2024-4479MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_en...
CVE-2024-3815MEDIUM4.8The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page i...
CVE-2024-3814MEDIUM4.8The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module i...
CVE-2024-2544MEDIUM6.4The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a miss...
CVE-2024-21988MEDIUM5.3StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of se...
CVE-2024-37889MEDIUM6.5MyFinances is a web application for managing finances. MyFinances has a way to access other customer invoices while sign...
CVE-2024-37888MEDIUM6.1The Open Link is a CKEditor plugin, extending context menu with a possibility to open link in a new tab. The vulnerabili...
CVE-2024-36599MEDIUM6.1A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2024-5659MEDIUM6.5Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result...
CVE-2024-37886MEDIUM4.7user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into acceptin...
CVE-2024-37884MEDIUM5.4Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versi...
CVE-2024-37883MEDIUM4.3Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integra...
CVE-2024-37317MEDIUM4.6The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder c...
CVE-2024-37316MEDIUM4.6Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachmen...
CVE-2024-37315MEDIUM4.3Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore ...
CVE-2024-33373MEDIUM6.3An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single...
CVE-2024-37312MEDIUM6.3user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an at...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now