2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-57372MEDIUM6.1Cross Site Scripting vulnerability in InformationPush master version allows a remote attacker to obtain sensitive inform...
CVE-2024-57370MEDIUM6.1Cross Site Scripting vulnerability in sunnygkp10 Online Exam System master version allows a remote attacker to obtain se...
CVE-2024-57369MEDIUM6.4Clickjacking vulnerability in typecho v1.2.1.
CVE-2024-13026MEDIUM6.1A vulnerability exists in Algo Edge up to 2.1.1 - a previously used (legacy) component of navify® Algorithm Suite. The ...
CVE-2024-53683MEDIUM5.6A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An...
CVE-2024-45832MEDIUM4.3Hard-coded credentials were included as part of the application binary. These credentials served as part of the applica...
CVE-2024-26157MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26156MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26154MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-50967MEDIUM6.5The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability....
CVE-2024-10498MEDIUM6.9CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a...
CVE-2024-13378MEDIUM5.4The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i...
CVE-2024-12370MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-11139MEDIUM4.6CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l...
CVE-2024-13386MEDIUM6.4The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ...
CVE-2024-13367MEDIUM6.5The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do...
CVE-2024-13366MEDIUM6.1The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio...
CVE-2024-12637MEDIUM5.3The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-12598MEDIUM6.4The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ p...
CVE-2024-12508MEDIUM6.4The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g...
CVE-2024-12466MEDIUM6.1The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all v...
CVE-2024-12203MEDIUM4.4The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in ...
CVE-2024-11146MEDIUM6.3TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-...
CVE-2024-10799MEDIUM6.5The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via th...
CVE-2024-13434MEDIUM6.1The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramete...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now