2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4634MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg...
CVE-2024-4617MEDIUM6.4The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ ...
CVE-2024-4400MEDIUM5.4The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-4385MEDIUM5.4The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up ...
CVE-2024-4288MEDIUM5.4The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Sto...
CVE-2024-35302MEDIUM6.1In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible
CVE-2024-35301MEDIUM5.5In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token
CVE-2024-35300MEDIUM6.1In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible
CVE-2024-4975MEDIUM6.1A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue...
CVE-2024-4974MEDIUM6.1A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an ...
CVE-2024-4968MEDIUM6.1A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected ...
CVE-2024-4391MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event ...
CVE-2024-4263MEDIUM5.4A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with onl...
CVE-2024-3887MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form ...
CVE-2024-3851MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper valida...
CVE-2024-30309MEDIUM5.5Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ...
CVE-2024-30308MEDIUM5.5Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could ...
CVE-2024-30298MEDIUM5.5Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead ...
CVE-2024-30281MEDIUM5.5Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that coul...
CVE-2024-20793MEDIUM5.5Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to dis...
CVE-2024-4546MEDIUM6.4The Custom Post Type Attachment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pdf_...
CVE-2024-4478MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Stack Gro...
CVE-2024-4843MEDIUM4.3ePO doesn't allow a regular privileged user to delete tasks or assignments. Insecure direct object references that allow...
CVE-2024-4635MEDIUM6.4The Menu Icons by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘add_mime_type’ fu...
CVE-2024-4318MEDIUM6.5The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now