2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49807MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to stored...
CVE-2024-47116MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-...
CVE-2024-47103MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-...
CVE-2024-45089MEDIUM4.3IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition EBICS server could allo...
CVE-2024-40696MEDIUM5.4IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.3 Standard Edition is vulnerable to cross-...
CVE-2024-11741MEDIUM4.3Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not...
CVE-2024-57948MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mac802154: check local interfaces before deleting s...
CVE-2024-13662MEDIUM6.4The eHive Objects Image Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ehive_o...
CVE-2024-12415MEDIUM6.5The The AI Infographic Maker plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, ...
CVE-2024-12037MEDIUM6.4The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) p...
CVE-2024-44055MEDIUM5.4Server-Side Request Forgery (SSRF) vulnerability in brandexponents Oshine Modules oshine-modules.This issue affects Oshi...
CVE-2024-13566MEDIUM6.4The WP DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all version...
CVE-2024-13157MEDIUM6.4The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross...
CVE-2024-53007MEDIUM6.4Bentley Systems ProjectWise Integration Server before 10.00.03.288 allows unintended SQL query execution by an authentic...
CVE-2024-13530MEDIUM4.3The Custom Login Page Styler – Limit Login Attempts – Restrict Content With Login – Redirect After Login – Change Login ...
CVE-2024-13623MEDIUM5.9The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-13717MEDIUM4.3The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data du...
CVE-2024-13424MEDIUM4.3The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capab...
CVE-2024-13415MEDIUM4.3The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized acc...
CVE-2024-13226MEDIUM6.1The A5 Custom Login Page WordPress plugin through 2.8.1 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-13225MEDIUM6.1The ECT Home Page Products WordPress plugin through 1.9 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-13224MEDIUM6.1The SlideDeck 1 Lite Content Slider WordPress plugin through 1.4.8 does not sanitise and escape a parameter before outpu...
CVE-2024-13223MEDIUM6.1The Tabulate WordPress plugin through 2.10.3 does not sanitise and escape some parameters before outputting them back in...
CVE-2024-13222MEDIUM6.1The User Messages WordPress plugin through 1.2.4 does not sanitise and escape a parameter before outputting it back in t...
CVE-2024-13221MEDIUM6.1The Fantastic ElasticSearch WordPress plugin through 4.1.0 does not sanitise and escape a parameter before outputting it...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now