2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-1534MEDIUM5.4The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode...
CVE-2024-2136MEDIUM5.4The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Hea...
CVE-2024-1506MEDIUM5.4The Prime Slider – Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title...
CVE-2024-1419MEDIUM5.4The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ attrib...
CVE-2024-1720MEDIUM6.1The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is ...
CVE-2024-1500MEDIUM5.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Logo ...
CVE-2024-1377MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_meta_ta...
CVE-2024-1366MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘archive_title_...
CVE-2024-28216MEDIUM5.4nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which ...
CVE-2024-1761MEDIUM5.4The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all v...
CVE-2024-28097MEDIUM5.4Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting all...
CVE-2024-28096MEDIUM5.4Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowi...
CVE-2024-28095MEDIUM5.4News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing...
CVE-2024-1460MEDIUM4.4MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code...
CVE-2024-1443MEDIUM4.4MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code ...
CVE-2024-24389MEDIUM6.1A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts o...
CVE-2024-2236MEDIUM5.9A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to ...
CVE-2024-28111MEDIUM6.5Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canaryt...
CVE-2024-2215MEDIUM6.1A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers ...
CVE-2024-28174MEDIUM5.8In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized i...
CVE-2024-28173MEDIUM4.3In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed
CVE-2024-28162MEDIUM4.2In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable S...
CVE-2024-28161MEDIUM5.3In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation ...
CVE-2024-28159MEDIUM4.3A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with ...
CVE-2024-28158MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now