2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-34071MEDIUM6.1Umbraco is an ASP.NET CMS used by more than 730.000 websites. Umbraco has an endpoint that is vulnerable to open redirec...
CVE-2024-35180MEDIUM6.1OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `ca...
CVE-2024-3268MEDIUM5.3The YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin for WordPress plugin for WordPress is vulnerable to...
CVE-2024-4876MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘p...
CVE-2024-4619MEDIUM5.4The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to DOM-Based Stored Cro...
CVE-2024-4361MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteo...
CVE-2024-4700MEDIUM5.4The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-4695MEDIUM5.4The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in ...
CVE-2024-4553MEDIUM5.4The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2024-4875MEDIUM4.3The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification of data|loss...
CVE-2024-3345MEDIUM5.4The ShopLentor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woolentorsearch shortc...
CVE-2024-4710MEDIUM6.4The UberMenu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ubermenu-col, ubermenu_m...
CVE-2024-4470MEDIUM5.4The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-4372MEDIUM5.4The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users...
CVE-2024-4289MEDIUM6.1The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting ...
CVE-2024-4061MEDIUM4.8The Survey Maker WordPress plugin before 4.2.9 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-2189MEDIUM6.1The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget...
CVE-2024-4943MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘has_field_link_rel’ parameter in a...
CVE-2024-3155MEDIUM6.4The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPre...
CVE-2024-0816MEDIUM5.5The buffer overflow vulnerability in the DX3300-T1 firmware version V5.50(ABVY.4)C0 could allow an authenticated local a...
CVE-2024-35195MEDIUM5.6Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is ...
CVE-2024-35194MEDIUM5.3Minder is a software supply chain security platform. Prior to version 0.0.50, Minder engine is susceptible to a denial o...
CVE-2024-35192MEDIUM5.5Trivy is a security scanner. Prior to 0.51.2, if a malicious actor is able to trigger Trivy to scan container images fro...
CVE-2024-35191MEDIUM4.4Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include mali...
CVE-2024-33901MEDIUM6.5Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in t...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now