2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49231MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cyclop WordPress V...
CVE-2024-49230MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in harry005 Ajax Cust...
CVE-2024-49228MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Edwin Rivera bVers...
CVE-2024-49225MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in swebdeveloper wpPr...
CVE-2024-49224MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mahesh_9696 Mitm B...
CVE-2024-10057MEDIUM5.4The RSS Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rfw-youtube-video...
CVE-2024-4740HIGH7.5MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded credentials. This vulnerab...
CVE-2024-4739HIGH7.5The lack of access restriction to a resource from unauthorized users makes MXsecurity software versions v1.1.0 and prior...
CVE-2024-47487HIGH8.8There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user ...
CVE-2024-47486MEDIUM6.1There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts in...
CVE-2024-47485CRITICAL9.8There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build ma...
CVE-2024-10080MEDIUM5.4The WP Easy Post Types plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to...
CVE-2024-10079HIGH8.8The WP Easy Post Types plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4....
CVE-2024-10078MEDIUM6.3The WP Easy Post Types plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to ...
CVE-2024-10055MEDIUM5.4The Click to Chat – WP Support All-in-One Floating Widget plugin for WordPress is vulnerable to Stored Cross-Site Script...
CVE-2024-9703MEDIUM5.4The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' short...
CVE-2024-9206MEDIUM6.1The MAS Companies For WP Job Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use...
CVE-2024-47793MEDIUM5.4Stored cross-site scripting vulnerability exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. When acces...
CVE-2024-46897LOW3.8Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and e...
CVE-2024-38820MEDIUM5.3The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() ...
CVE-2024-9892MEDIUM4.8The Add Widget After Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all...
CVE-2024-9848MEDIUM5.4The Product Customizer Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in a...
CVE-2024-9452MEDIUM5.4The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up t...
CVE-2024-9383MEDIUM6.1The Parcel Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all ve...
CVE-2024-9382MEDIUM6.1The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parame...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now