2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4392MEDIUM5.4The Jetpack – WP Security, Backup, Speed, & Growth plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2024-4333MEDIUM5.4The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elem...
CVE-2024-4144MEDIUM6.5The Simple Basic Contact Form plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all v...
CVE-2024-4139MEDIUM4.3Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu...
CVE-2024-4138MEDIUM4.3Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resu...
CVE-2024-3579MEDIUM6.1Open-source project Online Shopping System Advanced is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker m...
CVE-2024-3374MEDIUM5.3An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to atte...
CVE-2024-3241MEDIUM5.4The Ultimate Blocks WordPress plugin before 3.1.7 does not validate and escape some of its block options before outputt...
CVE-2024-35012MEDIUM6.3idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu...
CVE-2024-35011MEDIUM5.4idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoType_deal.php?mu...
CVE-2024-34914MEDIUM5.3php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. Th...
CVE-2024-34717MEDIUM5.3PrestaShop is an open source e-commerce web application. In PrestaShop 8.1.5, any invoice can be downloaded from front-o...
CVE-2024-34716MEDIUM6.1PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects Pr...
CVE-2024-34712MEDIUM6.5Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.re...
CVE-2024-34358MEDIUM5.3TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E...
CVE-2024-34357MEDIUM5.4TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E...
CVE-2024-34356MEDIUM5.4TYPO3 is an enterprise content management system. Starting in version 9.0.0 and prior to versions 9.5.48 ELTS, 10.4.45 E...
CVE-2024-34355MEDIUM5.4TYPO3 is an enterprise content management system. Starting in version 13.0.0 and prior to version 13.1.1, the history ba...
CVE-2024-34243MEDIUM5.4Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
CVE-2024-34191MEDIUM6.5htmly v2.9.6 was discovered to contain an arbitrary file deletion vulnerability via the delete_post() function at admin....
CVE-2024-33867MEDIUM4.8An issue was discovered in linqi before 1.4.0.1 on Windows. There is a hardcoded password salt.
CVE-2024-33866MEDIUM5.5An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/DocumentTemplate/{GUID] XSS.
CVE-2024-33864MEDIUM5.9An issue was discovered in linqi before 1.4.0.1 on Windows. There is SSRF via Document template generation; i.e., via re...
CVE-2024-33647MEDIUM6.5A vulnerability has been identified in Polarion ALM (All versions < V2404.0). The Apache Lucene based query engine in th...
CVE-2024-33583MEDIUM4.8A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now