2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4942MEDIUM4.8The Custom Dash plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ...
CVE-2024-4788MEDIUM4.3The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-4705MEDIUM5.4The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials ...
CVE-2024-2350MEDIUM5.4The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAF...
CVE-2024-0910MEDIUM5.3The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a...
CVE-2024-0912MEDIUM4.2Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server wil...
CVE-2024-27381MEDIUM6An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I...
CVE-2024-27380MEDIUM6An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. I...
CVE-2024-20405MEDIUM6.1A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2024-20404MEDIUM5.3A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker t...
CVE-2024-24789MEDIUM5.5The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implement...
CVE-2024-4812MEDIUM4.8A flaw was found in the Katello plugin for Foreman, where it is possible to store malicious JavaScript code in the "Desc...
CVE-2024-3716MEDIUM6.2A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue le...
CVE-2024-35673MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Pure Chat by Ruby Pure Chat.This issue affects Pure Chat: from n/a th...
CVE-2024-5459MEDIUM4.3The Restaurant Menu and Food Ordering plugin for WordPress is vulnerable to unauthorized creation of data due to a missi...
CVE-2024-3469MEDIUM6.1The GP Premium plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the message parameter in all ver...
CVE-2024-4001MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_logi...
CVE-2024-5536MEDIUM5.4The GamiPress – Link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's gamipress_link s...
CVE-2024-5571MEDIUM5.4The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-4821MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-5453MEDIUM4.3The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized modification ...
CVE-2024-5439MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Reflected Cross-Site Scripting via the custom_url parameter in all vers...
CVE-2024-5006MEDIUM5.4The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-4939MEDIUM5.4The Weaver Xtreme Theme Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's div s...
CVE-2024-5222MEDIUM5.4The Responsive Addons – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme. plugin for Wo...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now