2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-53386MEDIUM6.1Stage.js through 0.8.10 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but does not di...
CVE-2024-53382MEDIUM5.4Prism (aka PrismJS) through 1.29.0 allows DOM Clobbering (with resultant XSS for untrusted input that contains HTML but ...
CVE-2024-36353MEDIUM6.5Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem...
CVE-2024-55907MEDIUM5.3IBM Cognos Analytics Mobile 1.1 for iOS application could allow an attacker to reverse engineer the codebase to gain kno...
CVE-2024-41778MEDIUM6.5IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, whi...
CVE-2024-13546MEDIUM4.3The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu...
CVE-2024-13697MEDIUM6.5The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu...
CVE-2024-13806MEDIUM6.5The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and incl...
CVE-2024-13901MEDIUM4.8The Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site plugin for WordPress is vulnerable to...
CVE-2024-9217MEDIUM6.1The Currency Switcher for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the us...
CVE-2024-9212MEDIUM6.1The SKU Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
CVE-2024-13750MEDIUM6.5The Multilevel Referral Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'or...
CVE-2024-13746MEDIUM6.5The Booking Calendar and Notification plugin for WordPress is vulnerable to unauthorized access, modification, and loss ...
CVE-2024-13559MEDIUM6.4The TemplatesNext ToolKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tx_woo_wis...
CVE-2024-13518MEDIUM4.3The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-13358MEDIUM4.3The BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages plugin for WordPress is vulnerable to...
CVE-2024-54175MEDIUM5.5IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow a local user to cause a denial of service due to an improper c...
CVE-2024-44754MEDIUM6.8Cryptographic key extraction from internal flash in Minut M2 with firmware version #15142 allows physically proximate at...
CVE-2024-10860MEDIUM4.3The NextMove Lite – Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized submission of data...
CVE-2024-9019MEDIUM5.4The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-13851MEDIUM4.8The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and includi...
CVE-2024-13832MEDIUM4.3The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, an...
CVE-2024-13716MEDIUM4.3The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit...
CVE-2024-13469MEDIUM5.4The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link i...
CVE-2024-12820MEDIUM5.4The MK Google Directions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MKGD' short...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now