2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1767MEDIUM5.4The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up ...
CVE-2024-1320MEDIUM6.1The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
CVE-2024-1125MEDIUM5.4The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data d...
CVE-2024-1124MEDIUM4.3The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending ...
CVE-2024-1123MEDIUM6.5The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification o...
CVE-2024-28180MEDIUM4.3Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An atta...
CVE-2024-28176MEDIUM5.9jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web ...
CVE-2024-28122MEDIUM6.8 JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerabili...
CVE-2024-28753MEDIUM6.5RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.
CVE-2024-21901MEDIUM4.7A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authe...
CVE-2024-21900MEDIUM6.5An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnera...
CVE-2024-2319MEDIUM6.1Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could sto...
CVE-2024-2316MEDIUM4.3A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnera...
CVE-2024-2298MEDIUM4.3The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi...
CVE-2024-1851MEDIUM6.5The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a mi...
CVE-2024-27612MEDIUM6.2Numbas editor before 7.3 mishandles editing of themes and extensions.
CVE-2024-1987MEDIUM5.4The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shor...
CVE-2024-2285MEDIUM6.1A vulnerability, which was classified as problematic, has been found in boyiddha Automated-Mess-Management-System 1.0. A...
CVE-2024-2284MEDIUM6.1A vulnerability classified as problematic was found in boyiddha Automated-Mess-Management-System 1.0. Affected by this v...
CVE-2024-2277MEDIUM4.3A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problem...
CVE-2024-26313MEDIUM5.4Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a stored cross-site scripting (XSS) vulnerability. A remote...
CVE-2024-25848MEDIUM5.9In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection ...
CVE-2024-23297MEDIUM5.5The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. ...
CVE-2024-23295MEDIUM5.5A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An ...
CVE-2024-23293MEDIUM4.6This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonom...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now