2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4087MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-3565MEDIUM5.4The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-4711MEDIUM5.4The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-2933MEDIUM6.4The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the S...
CVE-2024-34006MEDIUM4.3The site log report required additional encoding of event descriptions to ensure any HTML in the content is displayed in...
CVE-2024-34005MEDIUM6.5In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-34004MEDIUM6.5In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-34003MEDIUM5.9In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-34002MEDIUM6.5In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with ...
CVE-2024-36845MEDIUM4.3An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (D...
CVE-2024-34000MEDIUM4.3ID numbers displayed in the lesson overview report required additional sanitizing to prevent a stored XSS risk.
CVE-2024-33998MEDIUM5.4Insufficient escaping of participants' names in the participants page table resulted in a stored XSS risk when interacti...
CVE-2024-33997MEDIUM6.1Additional sanitizing was required when opening the equation editor to prevent a stored XSS risk when editing another us...
CVE-2024-33996MEDIUM6.2Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events w...
CVE-2024-22060MEDIUM4.9An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, hi...
CVE-2024-31908MEDIUM5.4IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to stored cross-site scripting. This vulnerability allows users t...
CVE-2024-31907MEDIUM5.4IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2024-31889MEDIUM5.4IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2024-22338MEDIUM5.5IBM Security Verify Access OIDC Provider 22.09 through 23.03 could disclose sensitive information to a local user due to...
CVE-2024-5347MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'arrow' attribu...
CVE-2024-5041MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ha-ia-content-...
CVE-2024-4160MEDIUM5.4The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packag...
CVE-2024-5524MEDIUM5.3Information exposure vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows unregistered us...
CVE-2024-5427MEDIUM5.4The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is v...
CVE-2024-4379MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Glob...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now