2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-10332MEDIUM6.1A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacke...
CVE-2024-10180MEDIUM5.4The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-8959MEDIUM6.4The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-5608HIGH8.1Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature...
CVE-2024-49703MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam WpE...
CVE-2024-49691HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc...
CVE-2024-49683MEDIUM5.3Missing Authorization vulnerability in Magazine3 Schema & Structured Data for WP & AMP schema-and-structured-data-for-wp...
CVE-2024-49682MEDIUM6.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in wp.insider Simple Membership simple-membership allo...
CVE-2024-49681CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in activity-log.com W...
CVE-2024-9650MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all...
CVE-2024-9214MEDIUM6.1The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
CVE-2024-10331HIGH8.8A vulnerability, which was classified as critical, has been found in PHPGurukul Vehicle Record System 1.0. This issue af...
CVE-2024-10176MEDIUM6.4The Compact WP Audio Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_embe...
CVE-2024-8312MEDIUM5.4An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17...
CVE-2024-6826MEDIUM6.5An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17....
CVE-2024-8717MEDIUM6.1The PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-10050MEDIUM4.3The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to...
CVE-2024-9943MEDIUM6.3The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Cross...
CVE-2024-9531MEDIUM4.3The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unaut...
CVE-2024-8667MEDIUM4.3The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ...
CVE-2024-6049HIGH7.5The web server of Lawo AG vsm LTC Time Sync (vTimeSync) is affected by a "..." (triple dot) path traversal vulnerability...
CVE-2024-9865MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-9864MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-40595MEDIUM5.3An authentication-bypass issue in the RDP component of One Identity Safeguard for Privileged Sessions (SPS) On Premise b...
CVE-2024-9374MEDIUM6.1The Terms descriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now