2024 CVE Vulnerabilities
39,247 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-32082 | MEDIUM | 6.1 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site al... |
| CVE-2024-31093 | HIGH | 7.1 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Kaloyan K. Tsvetkov Broken Images allows Cross-Site Scripting (XSS).T... |
| CVE-2024-31086 | HIGH | 7.1 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Change default login logo,url and title allows Cross-Site S... |
| CVE-2024-30545 | HIGH | 7.1 | 0.2% | Apr 15, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Nick Powers Social Author Bio allows Stored XSS.This issue affects So... |
| CVE-2024-32454 | MEDIUM | 4.4 | 0.3% | Apr 15, 2024 | Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wap... |
| CVE-2024-32453 | MEDIUM | 4.8 | 0.3% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows St... |
| CVE-2024-32429 | MEDIUM | 4.8 | 0.3% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Foo... |
| CVE-2024-32428 | MEDIUM | 4.8 | 0.3% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW... |
| CVE-2024-32149 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for... |
| CVE-2024-32147 | MEDIUM | 5.4 | 0.3% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team -... |
| CVE-2024-32145 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google... |
| CVE-2024-32140 | MEDIUM | 5.4 | 0.3% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in libsyn Libsyn Publ... |
| CVE-2024-32138 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short... |
| CVE-2024-32133 | MEDIUM | 6.1 | 0.4% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenie... |
| CVE-2024-32079 | MEDIUM | 6.5 | 0.3% | Apr 15, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Ad... |
| CVE-2024-3771 | HIGH | 8.8 | 0.8% | Apr 15, 2024 | A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is... |
| CVE-2024-32489 | MEDIUM | 6.1 | 0.6% | Apr 15, 2024 | TCPDF before 6.7.4 mishandles calls that use HTML syntax. |
| CVE-2024-32488 | HIGH | 7.8 | 0.2% | Apr 15, 2024 | In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak p... |
| CVE-2024-3770 | CRITICAL | 9.8 | 0.8% | Apr 15, 2024 | A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vul... |
| CVE-2024-2858 | MEDIUM | 4.8 | 0.2% | Apr 15, 2024 | The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow att... |
| CVE-2024-2857 | MEDIUM | 6.1 | 0.2% | Apr 15, 2024 | The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add butt... |
| CVE-2024-2836 | MEDIUM | 4.8 | 0.5% | Apr 15, 2024 | The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape ... |
| CVE-2024-2739 | HIGH | 8.7 | 0.3% | Apr 15, 2024 | The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers... |
| CVE-2024-1849 | MEDIUM | 5.4 | 0.5% | Apr 15, 2024 | The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users... |
| CVE-2024-1846 | MEDIUM | 5.4 | 0.5% | Apr 15, 2024 | The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before o... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now