2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12520MEDIUM6.4The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...
CVE-2024-12519MEDIUM6.4The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_re...
CVE-2024-12412MEDIUM6.1The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin p...
CVE-2024-12407MEDIUM6.1The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via t...
CVE-2024-12116MEDIUM4.3The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in al...
CVE-2024-11915MEDIUM4.3The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and includi...
CVE-2024-11892MEDIUM6.4The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_...
CVE-2024-11874MEDIUM6.4The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordi...
CVE-2024-11758MEDIUM6.4The WP SPID Italia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all v...
CVE-2024-11386MEDIUM6.4The GatorMail SmartForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gatormailsm...
CVE-2024-42173MEDIUM4.8HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of acco...
CVE-2024-42171MEDIUM6.4HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL...
CVE-2024-42170MEDIUM6.8HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this by sending crafted URL...
CVE-2024-12587MEDIUM6.1The Contact Form Master WordPress plugin through 1.0.7 does not sanitise and escape a parameter before outputting it ba...
CVE-2024-12304MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-12505MEDIUM6.4The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in ...
CVE-2024-12472MEDIUM4.3The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3...
CVE-2024-12204MEDIUM5.4The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne...
CVE-2024-11327MEDIUM6.1The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is...
CVE-2024-9133MEDIUM5.6A user with administrator privileges is able to retrieve authentication tokens
CVE-2024-7142MEDIUM4.6On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA...
CVE-2024-47517MEDIUM6.8Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVE-2024-7095MEDIUM4.3On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s...
CVE-2024-5872MEDIUM6.5On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, whi...
CVE-2024-54998MEDIUM5.4MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now