2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-33944MEDIUM6.5Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce...
CVE-2024-3005MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-33930MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share Thi...
CVE-2024-33922MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Medi...
CVE-2024-33913CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability leading to Arbitrary File Upload in Xserver Migrator.This issue affects ...
CVE-2024-33911HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Weblizar School Ma...
CVE-2024-3955CRITICAL9.8URL GET parameter "logtime" utilized within the "downloadlog" function from "cbpi/http_endpoints/http_system.py" is subs...
CVE-2024-32638MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forwa...
CVE-2024-3883MEDIUM5.4The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all vers...
CVE-2024-32114HIGH8.8In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and...
CVE-2024-3280MEDIUM6.4The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us...
CVE-2024-3490MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-round...
CVE-2024-32971CRITICAL9Apollo Router is a configurable, graph router written in Rust to run a federated supergraph that uses Apollo Federation ...
CVE-2024-32962CRITICAL10xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default configuratio...
CVE-2024-32882LOW2.7Wagtail is an open source content management system built on Django. In affected versions if a model has been made avail...
CVE-2024-3481MEDIUM5.2The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attacke...
CVE-2024-3478MEDIUM6.1The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attack...
CVE-2024-3477MEDIUM4.3The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers...
CVE-2024-3476HIGH8.8The Side Menu Lite WordPress plugin before 4.2.1 does not have CSRF checks in some bulk actions, which could allow atta...
CVE-2024-3475HIGH7.5The Sticky Buttons WordPress plugin before 3.2.4 does not have CSRF checks in some bulk actions, which could allow atta...
CVE-2024-3474HIGH8.8The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk actions, which could allow at...
CVE-2024-3472MEDIUM5.9The Modal Window WordPress plugin before 5.3.10 does not have CSRF check in place when bulk deleting modals, which coul...
CVE-2024-3471LOW3.4The Button Generator WordPress plugin before 3.0 does not have CSRF check in place when bulk deleting, which could allo...
CVE-2024-2405MEDIUM4.5The Float menu WordPress plugin before 6.0.1 does not have CSRF check in its bulk actions, which could allow attackers ...
CVE-2024-4142CRITICAL9An Improper input validation vulnerability that could potentially lead to privilege escalation was discovered in JFrog A...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now