2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12436MEDIUM4.3The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF checks in some places, which could allow attacker...
CVE-2024-12280MEDIUM4.3The WP Customer Area WordPress plugin through 8.2.4 does not have CSRF check in place when deleting its logs, which coul...
CVE-2024-28771MEDIUM6.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr...
CVE-2024-28770MEDIUM6.5IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does not set the secure attr...
CVE-2024-31906MEDIUM6.2IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the s...
CVE-2024-13505MEDIUM4.8The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8...
CVE-2024-12334MEDIUM6.1The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-10636MEDIUM6.1The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via...
CVE-2024-35150MEDIUM5.3IBM Maximo Application Suite 8.10.12, 8.11.0, 9.0.1, and 9.1.0 - Monitor Component does not neutralize output that is wr...
CVE-2024-35145MEDIUM6.1IBM Maximo Application Suite 9.0.0 - Monitor Component is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2024-35144MEDIUM5.3IBM Maximo Application Suite 8.10, 8.11, and 9.0 - Monitor Component stores source code on the web server that could aid...
CVE-2024-35134MEDIUM5.3IBM Analytics Content Hub 2.0 could allow a remote attacker to obtain sensitive information when a detailed technical er...
CVE-2024-35114MEDIUM5.3IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to enumerate usernames due to an observable discr...
CVE-2024-35113MEDIUM6.5IBM Control Center 6.2.1 and 6.3.1 could allow an authenticated user to obtain sensitive information exposed through...
CVE-2024-35112MEDIUM4.3IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed techn...
CVE-2024-35111MEDIUM4.3IBM Control Center 6.2.1 and 6.3.1 could allow a remote attacker to obtain sensitive information when a detailed technic...
CVE-2024-13450MEDIUM6.5The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-13449MEDIUM4.3The Boom Fest plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-13599MEDIUM5.4The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ...
CVE-2024-13586MEDIUM5.4The Masy Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'justified-gallery' ...
CVE-2024-13551MEDIUM5.4The ABC Notation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'abcjs' shortcode in...
CVE-2024-13550MEDIUM6.5The ABC Notation plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.1.3 via th...
CVE-2024-13548MEDIUM5.4The Power Ups for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'magic-bu...
CVE-2024-13467MEDIUM6.1The WP Contact Form7 Email Spam Blocker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'po...
CVE-2024-13458MEDIUM5.4The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Store...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now