2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12109MEDIUM4.1The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.9 does not sanitize and escape a parameter ...
CVE-2024-11503MEDIUM6.1The WP Tabs WordPress plugin before 2.2.7 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-11273MEDIUM6.1The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s...
CVE-2024-11272MEDIUM6.1The Contact Form & SMTP Plugin for WordPress by PirateForms WordPress plugin before 2.6.0 does not sanitise and escape s...
CVE-2024-10703MEDIUM6.1The Registrations for the Events Calendar WordPress plugin before 2.13.4 does not sanitise and escape some of its setti...
CVE-2024-10679MEDIUM6.1The Quiz and Survey Master (QSM) WordPress plugin before 9.2.1 does not sanitise and escape some of its settings, which...
CVE-2024-10638MEDIUM4.1The Product Labels For Woocommerce (Sale Badges) WordPress plugin before 1.5.11 does not sanitize and escape a parameter...
CVE-2024-10566MEDIUM6.1The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10565MEDIUM6.1The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow...
CVE-2024-10560LOW3.5The Form Maker by 10Web WordPress plugin before 1.15.30 does not sanitise and escape some of its settings, which could ...
CVE-2024-10554LOW3.5The WordPress WP-Advanced-Search WordPress plugin before 3.3.9.3 does not sanitise and escape some of its settings, whic...
CVE-2024-10472MEDIUM5.9The Stylish Price List WordPress plugin before 7.1.12 does not sanitise and escape some of its settings, which could al...
CVE-2024-10210HIGH8.4An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an ...
CVE-2024-10105MEDIUM5.9The Job Postings WordPress plugin before 2.7.11 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-8315MEDIUM6.8An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may ...
CVE-2024-8314MEDIUM5.5An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in ...
CVE-2024-8313HIGH8.7An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an I...
CVE-2024-45484HIGH7.2An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used...
CVE-2024-45483HIGH7A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow ...
CVE-2024-45482HIGH8.5An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may a...
CVE-2024-45481HIGH8.5An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may all...
CVE-2024-45480CRITICAL9.2An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APR...
CVE-2024-10209HIGH8.5An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may ...
CVE-2024-10208MEDIUM5.1An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <...
CVE-2024-10207MEDIUM5.3A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticat...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now