2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12276MEDIUM6.5The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-13883MEDIUM4.3The WPUpper Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-13751MEDIUM5.4The 3D Photo Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'des[]' parameter in all ...
CVE-2024-13672MEDIUM5.4The Mini Course Generator | Embed mini-courses and interactive content plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-13537MEDIUM5.3The C9 Blocks plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.7.7. Th...
CVE-2024-13388MEDIUM5.4The TCBD Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbdtooltip_text' s...
CVE-2024-13379MEDIUM5.4The C9 Admin Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver...
CVE-2024-13235MEDIUM6.5The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the 'l...
CVE-2024-38657MEDIUM4.9External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version...
CVE-2024-7141MEDIUM5.9Versions of Gliffy Online prior to versions 4.14.0-7 contains a Cross Site Request Forgery (CSRF) flaw.
CVE-2024-55457MEDIUM6.5MasterSAM Star Gate 11 is vulnerable to directory traversal via /adama/adama/downloadService. An attacker can exploit th...
CVE-2024-54961MEDIUM6.5Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple ...
CVE-2024-54960MEDIUM6.5A SQL Injection vulnerability in Nagios XI 2024R1.2.2 allows a remote attacker to execute SQL injection via a crafted pa...
CVE-2024-54959MEDIUM6.1Nagios XI 2024R1.2.2 is vulnerable to a Cross-Site Request Forgery (CSRF) attack through the Favorites component, enabli...
CVE-2024-54958MEDIUM6.1Nagios XI 2024R1.2.2 is susceptible to a stored Cross-Site Scripting (XSS) vulnerability in the Tools page. This flaw al...
CVE-2024-49344MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages with Watson Assistant chat feature enabled the application estab...
CVE-2024-49337MEDIUM5.4IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation...
CVE-2024-6432MEDIUM5.4The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘conte...
CVE-2024-13855MEDIUM4.3The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...
CVE-2024-13849MEDIUM4.8The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2024-13802MEDIUM5.4The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_e...
CVE-2024-13748MEDIUM4.8The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title paramet...
CVE-2024-13520MEDIUM5.3The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized m...
CVE-2024-13888MEDIUM6.1The WPMobile.App plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 11.56. This i...
CVE-2024-13155MEDIUM5.4The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now