2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5310MEDIUM5.4A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of th...
CVE-2024-4366MEDIUM5.4The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘bloc...
CVE-2024-5060MEDIUM5.4The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored Cro...
CVE-2024-4485MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-4484MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-1376MEDIUM4.3The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing capability check...
CVE-2024-1332MEDIUM5.4The Custom Fonts – Host Your Fonts Locally plugin for WordPress is vulnerable to Stored Cross-Site Scripting via svg fil...
CVE-2024-0893MEDIUM4.3The Schema App Structured Data plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ...
CVE-2024-5142MEDIUM5.4Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticat...
CVE-2024-3718MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the p...
CVE-2024-36361MEDIUM6.8Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the ...
CVE-2024-1134MEDIUM5.4The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the SEO title and descr...
CVE-2024-3557MEDIUM5.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-2784MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Hover Card w...
CVE-2024-2618MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the size att...
CVE-2024-5205MEDIUM6.4The Videojs HTML5 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videojs_vide...
CVE-2024-4409MEDIUM4.3The WP-ViperGB plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1....
CVE-2024-5279MEDIUM5.3A vulnerability was found in Qiwen Netdisk up to 1.4.0. It has been declared as problematic. Affected by this vulnerabil...
CVE-2024-5294MEDIUM6.5D-Link DIR-3040 prog.cgi websSecurityHandler Memory Leak Denial-of-Service Vulnerability. This vulnerability allows netw...
CVE-2024-5244MEDIUM4.2TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent att...
CVE-2024-31843MEDIUM4.1An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as inp...
CVE-2024-5143MEDIUM6.8A user with device administrative privileges can change existing SMTP server settings on the device, without having to r...
CVE-2024-4365MEDIUM6.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_iframe_url_as_param_d...
CVE-2024-35085MEDIUM5.4J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMa...
CVE-2024-35082MEDIUM6.3J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xm...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now