2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4980MEDIUM6.4The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'id', 'mixColor'...
CVE-2024-31396MEDIUM6.6Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series ver...
CVE-2024-31395MEDIUM6.1Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ...
CVE-2024-31394MEDIUM6.5Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series v...
CVE-2024-30420MEDIUM4.4Server-side request forgery (SSRF) vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and ...
CVE-2024-30419MEDIUM5.4Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12, Ver.3.0.x series ...
CVE-2024-0451MEDIUM5The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-3519MEDIUM6.1The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the lang parameter ...
CVE-2024-3518MEDIUM6.5The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode(s) in all ver...
CVE-2024-33525MEDIUM4.3A Stored Cross-site Scripting (XSS) vulnerability in the "Import of organizational units and title of organizational uni...
CVE-2024-4154MEDIUM6.5In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged users to rename projec...
CVE-2024-34240MEDIUM6.1QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin func...
CVE-2024-22275MEDIUM4.9The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the v...
CVE-2024-36039MEDIUM6.3PyMySQL through 1.1.0 allows SQL injection if used with untrusted JSON input because keys are not escaped by escape_dict...
CVE-2024-31847MEDIUM6.1An issue was discovered in Italtel Embrace 1.6.4. A stored cross-site scripting (XSS) vulnerability allows authenticated...
CVE-2024-31845MEDIUM5.3An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that...
CVE-2024-31844MEDIUM5.3An issue was discovered in Italtel Embrace 1.6.4. The server does not properly handle application errors. In some cases,...
CVE-2024-31840MEDIUM6.5An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source cod...
CVE-2024-1721MEDIUM5.6Improper Verification of Cryptographic Signature vulnerability in HYPR Passwordless on Windows allows Malicious Software...
CVE-2024-33528MEDIUM4.7A Stored Cross-site Scripting (XSS) vulnerability in ILIAS 7 before 7.30 and ILIAS 8 before 8.11 allows remote authentic...
CVE-2024-33527MEDIUM5.4A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user" feature in ILIAS 7 bef...
CVE-2024-4452MEDIUM5.4The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in version...
CVE-2024-35385MEDIUM4.3An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_mk_ffi_sig function in ...
CVE-2024-35384MEDIUM5.5An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_array_length function i...
CVE-2024-35218MEDIUM4.8Umbraco CMS is an ASP.NET CMS used by more than 730.000 websites. Stored Cross-site scripting (XSS) enable attackers tha...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now