2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13500MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-13439MEDIUM4.3The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2024-10581MEDIUM4.3The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-13752MEDIUM6.5The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for Wo...
CVE-2024-13563MEDIUM5.4The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password s...
CVE-2024-13525MEDIUM6.5The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in ...
CVE-2024-13306MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-13208MEDIUM4.3The Maps Plugin using Google Maps for WordPress WordPress plugin before 1.9.4 does not sanitise and escape some of its ...
CVE-2024-10405MEDIUM5.3Brocade SANnav before SANnav 2.3.1b enables weak TLS ciphers on ports 443 and 18082. In case of a successful exploit, ...
CVE-2024-57790MEDIUM5.4IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root credentials stored in ...
CVE-2024-56463MEDIUM4.8IBM QRadar SIEM 7.5 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrar...
CVE-2024-57725MEDIUM6.5An issue in the Arcadyan Livebox Fibra PRV3399B_B_LT allows a remote or local attacker to modify the GPON link value wit...
CVE-2024-56477MEDIUM6.5IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the syst...
CVE-2024-52895MEDIUM6.5IBM i 7.4 and 7.5 is vulnerable to a database access denial of service caused by a bypass of a database capabilities res...
CVE-2024-13791MEDIUM4.9Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the down...
CVE-2024-13735MEDIUM5.4The HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce plugin for WordPress is vulnerable ...
CVE-2024-9601MEDIUM5.4The Qubely – Advanced Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’...
CVE-2024-57969MEDIUM4.3app/Model/Attribute.php in MISP before 2.4.198 ignores an ACL during a GUI attribute search.
CVE-2024-7052MEDIUM4.8The Forminator Forms WordPress plugin before 1.38.3 does not sanitise and escape some of its settings, which could allo...
CVE-2024-13692MEDIUM5.4The Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Feature...
CVE-2024-13493MEDIUM4.8The Sensly Online Presence WordPress plugin through 0.6 does not sanitise and escape some of its settings, which could a...
CVE-2024-10404MEDIUM4.4CalInvocationHandler in Brocade SANnav before 2.3.1b logs sensitive information in clear text. The vulnerability could...
CVE-2024-57782MEDIUM6.8An issue in Docker-proxy v18.09.0 allows attackers to cause a denial of service.
CVE-2024-56908MEDIUM6.8In Perfex Crm < 3.2.1, an authenticated attacker can send a crafted HTTP POST request to the affected upload_sales_file ...
CVE-2024-54951MEDIUM5.4Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now