2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32082MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site al...
CVE-2024-31093HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Kaloyan K. Tsvetkov Broken Images allows Cross-Site Scripting (XSS).T...
CVE-2024-31086HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Change default login logo,url and title allows Cross-Site S...
CVE-2024-30545HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Nick Powers Social Author Bio allows Stored XSS.This issue affects So...
CVE-2024-32454MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wap...
CVE-2024-32453MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows St...
CVE-2024-32429MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Foo...
CVE-2024-32428MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW...
CVE-2024-32149MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for...
CVE-2024-32147MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team -...
CVE-2024-32145MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google...
CVE-2024-32140MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in libsyn Libsyn Publ...
CVE-2024-32138MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short...
CVE-2024-32133MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenie...
CVE-2024-32079MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Ad...
CVE-2024-3771HIGH8.8A vulnerability was found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this issue is...
CVE-2024-32489MEDIUM6.1TCPDF before 6.7.4 mishandles calls that use HTML syntax.
CVE-2024-32488HIGH7.8In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalation could occur during update checks because weak p...
CVE-2024-3770CRITICAL9.8A vulnerability has been found in PHPGurukul Student Record System 3.20 and classified as critical. Affected by this vul...
CVE-2024-2858MEDIUM4.8The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow att...
CVE-2024-2857MEDIUM6.1The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add butt...
CVE-2024-2836MEDIUM4.8The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape ...
CVE-2024-2739HIGH8.7The Advanced Search WordPress plugin through 1.1.6 does not have CSRF checks in some places, which could allow attackers...
CVE-2024-1849MEDIUM5.4The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users...
CVE-2024-1846MEDIUM5.4The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now