2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-0786MEDIUM6.5The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress...
CVE-2024-0768MEDIUM4.3The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2024-0767MEDIUM4.3The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2024-0766MEDIUM4.3The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification...
CVE-2024-0682MEDIUM5.3The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5...
CVE-2024-0680MEDIUM5.3The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and incl...
CVE-2024-0433MEDIUM4.3The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-0432MEDIUM4.3The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-0431MEDIUM4.3The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-27913MEDIUM6.5ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service ...
CVE-2024-1943MEDIUM4.3The Yuki theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 1.3.14. Th...
CVE-2024-1568MEDIUM6.4The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and...
CVE-2024-1388MEDIUM4.3The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
CVE-2024-22723MEDIUM4.9Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attack...
CVE-2024-0550MEDIUM6.5A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relativ...
CVE-2024-1932MEDIUM4.8Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout
CVE-2024-1892MEDIUM6.5A Regular Expression Denial of Service (ReDoS) vulnerability exists in the XMLFeedSpider class of the scrapy/scrapy proj...
CVE-2024-26302MEDIUM4.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti...
CVE-2024-26301MEDIUM6.5A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a remote attacker authenti...
CVE-2024-26300MEDIUM4.8A vulnerability in the guest interface of ClearPass Policy Manager could allow an authenticated remote attacker to condu...
CVE-2024-26542MEDIUM6.1Cross Site Scripting vulnerability in Bonitasoft, S.A v.7.14. and fixed in v.9.0.2, 8.0.3, 7.15.7, 7.14.8 allows attacke...
CVE-2024-26299MEDIUM4.8A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote at...
CVE-2024-26298HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26297HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...
CVE-2024-26296HIGH8.8Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now