2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25066MEDIUM4.3RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a license file, resulting...
CVE-2024-13879MEDIUM5.5The Stream plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.2...
CVE-2024-47935MEDIUM6.7Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforc...
CVE-2024-13627MEDIUM4.7The OWL Carousel Slider WordPress plugin through 2.2 does not sanitise and escape a parameter before outputting it back ...
CVE-2024-13608MEDIUM4.7The Track Logins WordPress plugin through 1.0 does not sanitize and escape a parameter before using it in a SQL statemen...
CVE-2024-13603MEDIUM6.1The Wise Forms WordPress plugin through 1.2.0 does not sanitise and escape some of its settings, which could allow unaut...
CVE-2024-57970MEDIUM4libarchive through 3.7.7 has a heap-based buffer over-read in header_gnu_longlink in archive_read_support_format_tar.c v...
CVE-2024-13834MEDIUM5.4The Responsive Plus – Starter Templates, Advanced Features and Customizer Settings for Responsive Theme plugin for WordP...
CVE-2024-13500MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-13439MEDIUM4.3The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2024-10581MEDIUM4.3The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-13752MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-13563MEDIUM5.4The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s...
CVE-2024-13525MEDIUM6.5The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13306MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-13208MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-10405MEDIUM5.3Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ...
CVE-2024-57790MEDIUM5.4IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ...
CVE-2024-56463MEDIUM4.8IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar...
CVE-2024-57725MEDIUM6.5An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit...
CVE-2024-56477MEDIUM6.5IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst...
CVE-2024-52895MEDIUM6.5IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res...
CVE-2024-13791MEDIUM4.9Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down...
CVE-2024-13735MEDIUM5.4The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ...
CVE-2024-9601MEDIUM5.4The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now