2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-24718MEDIUM6.5Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6.
CVE-2024-24711MEDIUM4.3Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion ...
CVE-2024-23520MEDIUM4.3Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0.
CVE-2024-28126MEDIUM6.1Cross-site scripting vulnerability exists in 0ch BBS Script ver.4.00. An arbitrary script may be executed on the web bro...
CVE-2024-28034MEDIUM5.4Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web ...
CVE-2024-26018MEDIUM6.1Cross-site scripting vulnerability exists in TvRock 0.9t8a. An arbitrary script may be executed on the web browser of th...
CVE-2024-24805MEDIUM5.3Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator.This issue affects WP Dummy Content Gener...
CVE-2024-2889MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Lab WP-Lister L...
CVE-2024-2888MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Post and ...
CVE-2024-2303MEDIUM6.4The Easy Textillate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'textillate' shor...
CVE-2024-2170MEDIUM5.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the child page in...
CVE-2024-1745MEDIUM4.3The Testimonial Slider WordPress plugin before 2.3.7 does not properly ensure that a user has the necessary capabilities...
CVE-2024-29199MEDIUM5.3Nautobot is a Network Source of Truth and Network Automation Platform. A number of Nautobot URL endpoints were found to ...
CVE-2024-2732MEDIUM5.4The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'themify_post_...
CVE-2024-21914MEDIUM5.3 A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelVie...
CVE-2024-29179MEDIUM4.8phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. An attacker with ...
CVE-2024-29041MEDIUM6.1Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta ...
CVE-2024-29025MEDIUM5.3Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2024-28246MEDIUM5.4KaTeX is a JavaScript library for TeX math rendering on the web. Code that uses KaTeX's `trust` option, specifically tha...
CVE-2024-28245MEDIUM6.1KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressio...
CVE-2024-28244MEDIUM6.5KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressio...
CVE-2024-28243MEDIUM6.5KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressio...
CVE-2024-28108MEDIUM6.1phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Due to insufficie...
CVE-2024-28106MEDIUM5.4phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. By manipulating t...
CVE-2024-27300MEDIUM5.4phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The `email` field...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now