2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37360MEDIUM4.4Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-...
CVE-2024-53974MEDIUM5.4Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2024-45777MEDIUM6.7A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_ge...
CVE-2024-45081MEDIUM6.5IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 could allow an authenticated user to modif...
CVE-2024-28780MEDIUM5.9IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 Rich Client  uses weaker than expected cr...
CVE-2024-28776MEDIUM5.4IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to cross-site scripting. This ...
CVE-2024-13364MEDIUM5.3The Raptive Ads plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the site_...
CVE-2024-13363MEDIUM6.1The Raptive Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'poc' parameter in all vers...
CVE-2024-13339MEDIUM5.4The DeBounce Email Validator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and...
CVE-2024-13336MEDIUM4.3The Disable Auto Updates plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-13231MEDIUM5.3The WordPress Portfolio Builder – Portfolio Gallery plugin for WordPress is vulnerable to unauthorized modification of d...
CVE-2024-13854MEDIUM4.3The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions...
CVE-2024-13736MEDIUM6.1The Pure Chat – Live Chat & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘purechatWid...
CVE-2024-13719MEDIUM5.3The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ...
CVE-2024-13712MEDIUM4.9The Pollin plugin for WordPress is vulnerable to SQL Injection via the 'question' parameter in all versions up to, and i...
CVE-2024-13711MEDIUM6.1The Pollin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'question' parameter in all vers...
CVE-2024-13679MEDIUM5.4The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' sh...
CVE-2024-13676MEDIUM6.5The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'ima...
CVE-2024-13674MEDIUM6.4The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripti...
CVE-2024-13663MEDIUM6.4The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' s...
CVE-2024-13660MEDIUM6.4The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fsho...
CVE-2024-13657MEDIUM6.4The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocato...
CVE-2024-13591MEDIUM5.4The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-...
CVE-2024-13589MEDIUM6.4The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt...
CVE-2024-13462MEDIUM6.4The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now