2024 CVE Vulnerabilities

39,250 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-25905MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from...
CVE-2024-25904HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and S...
CVE-2024-24876HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: f...
CVE-2024-24872HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a ...
CVE-2024-24849HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects ...
CVE-2024-24843HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue...
CVE-2024-1081MEDIUM5.4The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-0593MEDIUM5.3The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorizatio...
CVE-2024-22235MEDIUM6.7VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access...
CVE-2024-25151MEDIUM5.4The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before se...
CVE-2024-1676MEDIUM5.4Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof se...
CVE-2024-1675HIGH8.8Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass ...
CVE-2024-1674HIGH8.8Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass n...
CVE-2024-1673HIGH8.8Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised th...
CVE-2024-1672MEDIUM5.4Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacke...
CVE-2024-1671MEDIUM6.5Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypa...
CVE-2024-1670HIGH8.8Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap cor...
CVE-2024-1669HIGH8.8Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of...
CVE-2024-1562MEDIUM5.3The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a ...
CVE-2024-1501MEDIUM4.7The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including...
CVE-2024-26269MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37...
CVE-2024-26266MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupport...
CVE-2024-25603MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 thr...
CVE-2024-1631CRITICAL9.1Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional p...
CVE-2024-1108HIGH8.2The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now