2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12637MEDIUM5.3The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-12598MEDIUM6.4The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ p...
CVE-2024-12508MEDIUM6.4The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g...
CVE-2024-12466MEDIUM6.1The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all v...
CVE-2024-12203MEDIUM4.4The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in ...
CVE-2024-11146MEDIUM6.3TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-...
CVE-2024-10799MEDIUM6.5The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via th...
CVE-2024-13434MEDIUM6.1The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramete...
CVE-2024-13401MEDIUM6.4The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_pay...
CVE-2024-13398MEDIUM6.4The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for...
CVE-2024-51462MEDIUM5.3IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter value...
CVE-2024-57785MEDIUM4.9Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uplo...
CVE-2024-57784MEDIUM5.5An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a direct...
CVE-2024-56144MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t...
CVE-2024-40514MEDIUM4.6Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via t...
CVE-2024-40513MEDIUM4.6An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload ...
CVE-2024-48460MEDIUM4.3An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the S...
CVE-2024-57577MEDIUM5.7Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the speed_dir parameter in the formSetSpeedWan fu...
CVE-2024-56515MEDIUM6.5Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnai...
CVE-2024-56136MEDIUM5.3Zulip server provides an open-source team chat that helps teams stay productive and focused. Zulip Server 7.0 and above ...
CVE-2024-52602MEDIUM5.3Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) i...
CVE-2024-36402MEDIUM5.3Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 ...
CVE-2024-57683MEDIUM4.3An access control issue in the component websURLFilterAddDel of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenti...
CVE-2024-57682MEDIUM6.5An information disclosure vulnerability in the component d_status.asp of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows u...
CVE-2024-57681MEDIUM5.3An access control issue in the component form2alg.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210 allows unauthenticated a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now