2024 CVE Vulnerabilities

39,243 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34097HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-34096HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-34095HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-34094HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-30312MEDIUM5.5Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili...
CVE-2024-30311MEDIUM5.5Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier Answer: are affected by an out-of-bounds read vulnerabili...
CVE-2024-30310HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that...
CVE-2024-30284HIGH7.8Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could...
CVE-2024-4010HIGH8.8The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification...
CVE-2024-4636MEDIUM6.4The Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-3824MEDIUM5.5The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings,...
CVE-2024-3823LOW2.4The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is mi...
CVE-2024-3822MEDIUM4.8The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not sanitise and escape a parameter before outputting it ...
CVE-2024-3749MEDIUM6.5The SP Project & Document Manager WordPress plugin through 4.71 lacks proper access controllers and allows a logged in u...
CVE-2024-3748MEDIUM6.5The SP Project & Document Manager WordPress plugin through 4.71 is missing validation in its upload function, allowing a...
CVE-2024-3634MEDIUM4.8The month name translation benaceur WordPress plugin before 2.3.8 does not sanitise and escape some of its settings, whi...
CVE-2024-3631MEDIUM4.3The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check when unlinking twitter accounts, which could ...
CVE-2024-3630MEDIUM5.4The HL Twitter WordPress plugin through 2014.1.18 does not sanitise and escape some of its settings, which could allow h...
CVE-2024-3629LOW2.4The HL Twitter WordPress plugin through 2014.1.18 does not have CSRF check in place when updating its settings, which co...
CVE-2024-3548MEDIUM6.1The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.2 does not sanitise and escape a parameter be...
CVE-2024-3407MEDIUM5.3The WP Prayer WordPress plugin through 2.0.9 does not have CSRF checks in some places, which could allow attackers to ma...
CVE-2024-3406HIGH8.8The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which c...
CVE-2024-3405HIGH7.6The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could a...
CVE-2024-4894MEDIUM5.3ITPison OMICARD EDM fails to properly filter specific URL parameter, allowing unauthenticated remote attackers to modif...
CVE-2024-4893CRITICAL9.8DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL c...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now