2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57277MEDIUM5.7InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.
CVE-2024-57095MEDIUM6.8SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-57041MEDIUM4.6A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code ...
CVE-2024-45077MEDIUM6.5IBM Maximo Asset Management 7.6.1.3 MXAPIASSET API is vulnerable to unrestricted file upload which allows authenticated ...
CVE-2024-41757MEDIUM5.9IBM Concert Software 1.0.0 and 1.0.1 could allow a remote attacker to obtain sensitive information, caused by the failur...
CVE-2024-40706MEDIUM4.3IBM InfoSphere Information Server 11.7 could allow a remote user to obtain sensitive version information that could aid ...
CVE-2024-13698MEDIUM6.5The Jobify - Job Board WordPress Theme for WordPress is vulnerable to unauthorized access and modification of data due t...
CVE-2024-57184MEDIUM5.5An issue was discovered in GPAC v0.8.0, as demonstrated by MP4Box. It contains a heap-based buffer overflow in gf_m2ts_p...
CVE-2024-11913MEDIUM5.4The Activity Plus Reloaded for BuddyPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all...
CVE-2024-10324MEDIUM4.3The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t...
CVE-2024-13594MEDIUM6.5The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofi...
CVE-2024-13572MEDIUM5.4The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting v...
CVE-2024-13542MEDIUM5.4The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Store...
CVE-2024-13354MEDIUM5.4The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulne...
CVE-2024-13335MEDIUM4.3The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unau...
CVE-2024-13583MEDIUM5.4The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_...
CVE-2024-12494MEDIUM5.4The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_ma...
CVE-2024-13683MEDIUM4.3The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2024-13680MEDIUM6.5The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL...
CVE-2024-13659MEDIUM5.4The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortco...
CVE-2024-11931MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior ...
CVE-2024-57556MEDIUM6.1Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary cod...
CVE-2024-57386MEDIUM6.1Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile...
CVE-2024-57329MEDIUM5.4HortusFox v3.9 contains a stored XSS vulnerability in the "Add Plant" function. The name input field does not sanitize o...
CVE-2024-57326MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the search.php file of the Online Pizza Delivery System 1...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now