2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-48023HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rconnect305 Restau...
CVE-2024-48022MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics S...
CVE-2024-48021HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Paterson Con...
CVE-2024-49320HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dennis Encyclopedi...
CVE-2024-48047MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce linked-variation-for...
CVE-2024-48043HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ShortPixel ShortPi...
CVE-2024-48038MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in tuxlog wp-Monalisa wp-monalisa.This issue affects wp-Monalisa: from n...
CVE-2024-48024HIGH7.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Fahad Mahmood Keep Backup Da...
CVE-2024-9898MEDIUM5.4The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc...
CVE-2024-45713MEDIUM4.4SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been...
CVE-2024-10068HIGH8.5A vulnerability was found in OpenSight Software FlashFXP 5.4.0.3970. It has been classified as critical. Affected is an ...
CVE-2024-9184HIGH7.2The SendPulse Free Web Push plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and...
CVE-2024-8920MEDIUM6.4The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2024-49392MEDIUM4.8Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro...
CVE-2024-49391HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files ...
CVE-2024-49390HIGH7.3Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files ...
CVE-2024-49389HIGH7.8Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files ...
CVE-2024-49386MEDIUM5.7Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows...
CVE-2024-10025CRITICAL9.1A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain text within the code. By e...
CVE-2024-9951MEDIUM6.1The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete...
CVE-2024-3187MEDIUM5.9This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6....
CVE-2024-3186MEDIUM5.3CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when ...
CVE-2024-3184MEDIUM5.9Multiple CWE-476 NULL Pointer Dereference vulnerabilities were found in GoAhead Web Server up to version 6.0.0 when comp...
CVE-2024-9213MEDIUM6.1The افزونه پیامک ووکامرس Persian WooCommerce SMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-9352MEDIUM4.3The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Cross-Site...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now