2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-0449MEDIUM4.8The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a...
CVE-2024-0447MEDIUM5The ArtiBot Free Chat Bot for WordPress WebSites plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2024-0385MEDIUM4.3The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check...
CVE-2024-0377MEDIUM5.3The LifterLMS – WordPress LMS Plugin for eLearning plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-0369MEDIUM4.3The Bulk Edit Post Titles plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2024-0326MEDIUM6.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Link...
CVE-2024-25155MEDIUM6.1In FileCatalyst Direct 3.8.8 and earlier through 3.8.6, the web server does not properly sanitize illegal characters in ...
CVE-2024-25154MEDIUM5.3Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to ...
CVE-2024-2247MEDIUM6.1JFrog Artifactory versions below 7.77.7, 7.82.1, are vulnerable to DOM-based cross-site scripting due to improper handli...
CVE-2024-26629MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nfsd: fix RELEASE_LOCKOWNER The test on so_count i...
CVE-2024-1508MEDIUM5.4The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'setti...
CVE-2024-1507MEDIUM5.4The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title...
CVE-2024-28668MEDIUM6.1DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/mychann...
CVE-2024-28667MEDIUM6.1DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/templet...
CVE-2024-28666MEDIUM5.5DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/media_a...
CVE-2024-28430MEDIUM6.1DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/catalog...
CVE-2024-28429MEDIUM5.5DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /dede/archive...
CVE-2024-2416MEDIUM6.5Cross-Site Request Forgery vulnerability in Movistar's 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnera...
CVE-2024-2123MEDIUM6.1The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-28623MEDIUM6.1RiteCMS v3.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component main_menu/edit_sec...
CVE-2024-27440MEDIUM4.8The Toyoko Inn official App for iOS versions prior to 1.13.0 and Toyoko Inn official App for Android versions prior 1.3....
CVE-2024-2412MEDIUM5.3The disabling function of the user registration page for Heimavista Rpage and Epage is not properly implemented, allowin...
CVE-2024-1582MEDIUM5.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-1421MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘b...
CVE-2024-1397MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now