2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3977MEDIUM4.8The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which coul...
CVE-2024-3972MEDIUM4.3The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2024-3971MEDIUM4.3The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could a...
CVE-2024-3966MEDIUM6.1The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated...
CVE-2024-3965MEDIUM5.4The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could...
CVE-2024-3754MEDIUM4.7The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could all...
CVE-2024-2218MEDIUM4.6The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which co...
CVE-2024-2122MEDIUM5.4The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via alb...
CVE-2024-23504MEDIUM5.3Missing Authorization vulnerability in WPManageNinja LLC Ninja Tables.This issue affects Ninja Tables: from n/a through ...
CVE-2024-1295MEDIUM6.5The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not pr...
CVE-2024-5469MEDIUM4.3DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an a...
CVE-2024-31160MEDIUM4.8The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke...
CVE-2024-31159MEDIUM4.8The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacke...
CVE-2024-27180MEDIUM6.7An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the refe...
CVE-2024-27179MEDIUM4.7Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. ...
CVE-2024-27175MEDIUM4.4Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can r...
CVE-2024-27163MEDIUM6.5Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 speci...
CVE-2024-27162MEDIUM6.1Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable...
CVE-2024-27161MEDIUM6.2all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the enc...
CVE-2024-27160MEDIUM6.2All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt th...
CVE-2024-27159MEDIUM6.2All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt th...
CVE-2024-27157MEDIUM6.8The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retr...
CVE-2024-27156MEDIUM6.8The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication ses...
CVE-2024-0892MEDIUM4.3The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2024-27154MEDIUM6.2Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/version...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now