2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13699MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘cursor’ parameter...
CVE-2024-27137MEDIUM5.3In Apache Cassandra it is possible for a local attacker without access to the Apache Cassandra process or configuration...
CVE-2024-13733MEDIUM5.4The SKT Blocks – Gutenberg based Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-13529MEDIUM6.5The SocialV - Social Network and Community BuddyPress Theme theme for WordPress is vulnerable to unauthorized access of ...
CVE-2024-13510MEDIUM6.1The ShopSite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5....
CVE-2024-13356MEDIUM6.5The DSGVO All in one for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-13403MEDIUM5.4The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vu...
CVE-2024-13514MEDIUM4.3The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Information Exposure in all versions u...
CVE-2024-12046MEDIUM4.3The Medical Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions u...
CVE-2024-13607MEDIUM4.3The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object ...
CVE-2024-12597MEDIUM5.4The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'b...
CVE-2024-13332MEDIUM6.1The TransFinanz WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the...
CVE-2024-13331MEDIUM6.1The WP Dream Carousel WordPress plugin through 1.0.1b does not sanitise and escape a parameter before outputting it back...
CVE-2024-13328MEDIUM6.1The Giga Messenger WordPress plugin through 2.3.1 does not sanitise and escape a parameter before outputting it back in...
CVE-2024-13327MEDIUM6.1The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13326MEDIUM6.1The iBuildApp WordPress plugin through 0.2.0 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2024-13325MEDIUM6.1The Glossy WordPress plugin through 2.3.5 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-13115MEDIUM6.1The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places,...
CVE-2024-13114MEDIUM6.1The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter...
CVE-2024-44449MEDIUM6.1Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive informat...
CVE-2024-57498MEDIUM4.8Cross Site Scripting vulnerability in sayski ForestBlog 20241223 allows a remote attacker to escalate privileges via the...
CVE-2024-57097MEDIUM4.8ClassCMS 4.8 is vulnerable to Cross Site Scripting (XSS) in class/admin/channel.php.
CVE-2024-56946MEDIUM5.3Denial of service in DNS-over-QUIC in Technitium DNS Server <= v13.2.2 allows remote attackers to permanently stop the s...
CVE-2024-11134MEDIUM6.5The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...
CVE-2024-11133MEDIUM5.3The Eventer plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the '...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now