2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12385MEDIUM6.1The WP Abstracts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-9020MEDIUM5.4The List category posts WordPress plugin before 0.90.3 does not validate and escape some of its shortcode attributes bef...
CVE-2024-13516MEDIUM6.1The Kubio AI Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet...
CVE-2024-13515MEDIUM6.1The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-12071MEDIUM5.3The Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media plugin for WordPress is vulnerab...
CVE-2024-11923MEDIUM5.5Under certain log settings the IAM or CORE service will log credentials in the iam logfile in Fortra Application Hub (Fo...
CVE-2024-57252MEDIUM4.3OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitr...
CVE-2024-57033MEDIUM6.1WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
CVE-2024-57372MEDIUM6.1Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform...
CVE-2024-57370MEDIUM6.1Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se...
CVE-2024-57369MEDIUM6.4Clickjacking vulnerability in typecho v1.2.1.
CVE-2024-13026MEDIUM6.1A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ...
CVE-2024-53683MEDIUM5.6A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An...
CVE-2024-45832MEDIUM4.3Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica...
CVE-2024-26157MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26156MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26154MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-50967MEDIUM6.5The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability....
CVE-2024-10498MEDIUM6.9CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a...
CVE-2024-13378MEDIUM5.4The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i...
CVE-2024-12370MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-11139MEDIUM4.6CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l...
CVE-2024-13386MEDIUM6.4The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ...
CVE-2024-13367MEDIUM6.5The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do...
CVE-2024-13366MEDIUM6.1The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now