2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57685MEDIUM5.3An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
CVE-2024-53543MEDIUM5.4NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-53542MEDIUM6.5Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim...
CVE-2024-57608MEDIUM6.5An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
CVE-2024-57026MEDIUM6.1TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al...
CVE-2024-5174MEDIUM5.3A flaw in Gliffy results in broken authentication through the reset functionality of the application.
CVE-2024-13822MEDIUM6.1The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter...
CVE-2024-13605MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ...
CVE-2024-12308MEDIUM5.4The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outp...
CVE-2024-13728MEDIUM6.1The Accept Donations with PayPal & Stripe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the r...
CVE-2024-13564MEDIUM5.4The Rife Elementor Extensions & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-13798MEDIUM5.3The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to unauthorized order creation in al...
CVE-2024-12467MEDIUM6.1The Pago por Redsys plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'Ds_MerchantParameters'...
CVE-2024-12038MEDIUM5.4The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-13873MEDIUM4.3The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to...
CVE-2024-55159MEDIUM4.2GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the SortName parameter at /system/l...
CVE-2024-55156MEDIUM5.5An XML External Entity (XXE) vulnerability in the deserializeArgs() method of Java SDK for CloudEvents v4.0.1 allows att...
CVE-2024-45673MEDIUM5.5IBM Security Verify Bridge Directory Sync 1.0.1 through 1.0.12, IBM Security Verify Gateway for Windows Login 1.0.1 thro...
CVE-2024-10222MEDIUM5.4The SVG Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions u...
CVE-2024-13846MEDIUM4.9The Indeed Ultimate Learning Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘post_id’ parame...
CVE-2024-13713MEDIUM6.5The WPExperts Square For GiveWP plugin for WordPress is vulnerable to SQL Injection via the 'post' parameter in all vers...
CVE-2024-13455MEDIUM5.4The igumbi Online Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'igumbi_cal...
CVE-2024-13648MEDIUM5.4The Maps for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'MapOnePoint' shortco...
CVE-2024-13461MEDIUM5.4The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-12452MEDIUM5.4The Ziggeo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ziggeo_event' shortcode i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now