2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-0611MEDIUM4.8The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sl...
CVE-2024-0378MEDIUM6.1The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-1775MEDIUM5.4The Nextend Social Login and Register plugin for WordPress is vulnerable to a self-based Reflected Cross-Site Scripting ...
CVE-2024-1592MEDIUM4.3The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version...
CVE-2024-25064MEDIUM4.3Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the at...
CVE-2024-25438MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Submission module of Pkp Ojs v3.3 allows attackers to execute arbitrar...
CVE-2024-25436MEDIUM6.1A cross-site scripting (XSS) vulnerability in the Production module of Pkp Ojs v3.3 allows attackers to execute arbitrar...
CVE-2024-25434MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-24512MEDIUM6.1Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the input subtitle ...
CVE-2024-24511MEDIUM6.1Cross Site Scripting vulnerability in Pkp OJS v.3.4 allows an attacker to execute arbitrary code via the Input Title com...
CVE-2024-27744MEDIUM6.1Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code ...
CVE-2024-27743MEDIUM6.1Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code ...
CVE-2024-23492MEDIUM5.7 A weak encoding is used to transmit credentials for WS203VICM.
CVE-2024-20328MEDIUM5.3A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the p...
CVE-2024-2075MEDIUM5.4A vulnerability was found in SourceCodester Daily Habit Tracker 1.0. It has been declared as problematic. Affected by th...
CVE-2024-2074MEDIUM6.3A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown proce...
CVE-2024-2072MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Flashcard Quiz App 1.0. This affects a...
CVE-2024-2071MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester FAQ Management System 1.0. Affect...
CVE-2024-27734MEDIUM6.1A Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows an attacker to execute arbitrary code via a crafted scrip...
CVE-2024-27559MEDIUM6.3Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /save_settings....
CVE-2024-27558MEDIUM6.1Stupid Simple CMS 1.2.4 is vulnerable to Cross Site Scripting (XSS) within the blog title of the settings.
CVE-2024-2070MEDIUM6.1A vulnerability classified as problematic was found in SourceCodester FAQ Management System 1.0. Affected by this vulner...
CVE-2024-2069MEDIUM5.3A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknow...
CVE-2024-2068MEDIUM6.1A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been rated as problematic. This issue ...
CVE-2024-27499MEDIUM6.5Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now