2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-54408MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in codehandling Youtube Video Grid youmax-channel-embeds-for-youtube-bus...
CVE-2024-54402MEDIUM4.3Missing Authorization vulnerability in Mohamed Abd Elhalim Arabic Webfonts arabic-webfonts allows Exploiting Incorrectly...
CVE-2024-54396MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in elmervillanueva Bet sport Free bet-sport-free allows Cross Site Reque...
CVE-2024-54384MEDIUM4.3Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incor...
CVE-2024-54382MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in boldthemes Bold Page Bui...
CVE-2024-54366MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in videogallery Vimeography vimeography allow...
CVE-2024-54360MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in premila Gutensee g...
CVE-2024-54356MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita mee...
CVE-2024-54354MEDIUM6.5Missing Authorization vulnerability in beat.k Termin-Kalender termin-kalender allows Stored XSS.This issue affects Termi...
CVE-2024-37251MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WPENGINE, INC. Advanced Custom Fields PRO.This issue affects Advanced...
CVE-2024-12092MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE...
CVE-2024-12091MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-12090MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator on Release 3DEXPERIE...
CVE-2024-12089MEDIUM5.4A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPER...
CVE-2024-12362MEDIUM5.3A vulnerability was found in InvoicePlane up to 1.6.1. It has been classified as problematic. This affects the function ...
CVE-2024-54682MEDIUM4.9Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to limit the file size fo...
CVE-2024-54083MEDIUM6.5Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12 fail to properly validate the ...
CVE-2024-48872MEDIUM4.8Mattermost versions 10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, and 9.5.x <= 9.5.12 fail to prevent concurrent...
CVE-2024-9679MEDIUM5.3A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previousl...
CVE-2024-9678MEDIUM4.9An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arb...
CVE-2024-12645MEDIUM6.5The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w...
CVE-2024-5333MEDIUM5.3The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticat...
CVE-2024-56112MEDIUM6.1CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.
CVE-2024-56087MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template...
CVE-2024-56085MEDIUM5.9An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now