2024 CVE Vulnerabilities
39,250 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-25905 | MEDIUM | 5.4 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from... |
| CVE-2024-25904 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and S... |
| CVE-2024-24876 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: f... |
| CVE-2024-24872 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a ... |
| CVE-2024-24849 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects ... |
| CVE-2024-24843 | HIGH | 8.8 | 0.2% | Feb 21, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue... |
| CVE-2024-1081 | MEDIUM | 5.4 | 0.3% | Feb 21, 2024 | The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2024-0593 | MEDIUM | 5.3 | 0.9% | Feb 21, 2024 | The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorizatio... |
| CVE-2024-22235 | MEDIUM | 6.7 | 0.2% | Feb 21, 2024 | VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access... |
| CVE-2024-25151 | MEDIUM | 5.4 | 0.5% | Feb 21, 2024 | The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before se... |
| CVE-2024-1676 | MEDIUM | 5.4 | 18.6% | Feb 21, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof se... |
| CVE-2024-1675 | HIGH | 8.8 | 10.4% | Feb 21, 2024 | Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass ... |
| CVE-2024-1674 | HIGH | 8.8 | 0.8% | Feb 21, 2024 | Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass n... |
| CVE-2024-1673 | HIGH | 8.8 | 0.8% | Feb 21, 2024 | Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised th... |
| CVE-2024-1672 | MEDIUM | 5.4 | 0.9% | Feb 21, 2024 | Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacke... |
| CVE-2024-1671 | MEDIUM | 6.5 | 0.7% | Feb 21, 2024 | Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypa... |
| CVE-2024-1670 | HIGH | 8.8 | 9.0% | Feb 21, 2024 | Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2024-1669 | HIGH | 8.8 | 1.0% | Feb 21, 2024 | Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of... |
| CVE-2024-1562 | MEDIUM | 5.3 | 0.4% | Feb 21, 2024 | The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2024-1501 | MEDIUM | 4.7 | 0.3% | Feb 21, 2024 | The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2024-26269 | MEDIUM | 6.1 | 0.6% | Feb 21, 2024 | Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37... |
| CVE-2024-26266 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupport... |
| CVE-2024-25603 | MEDIUM | 5.4 | 0.6% | Feb 21, 2024 | Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 thr... |
| CVE-2024-1631 | CRITICAL | 9.1 | 0.9% | Feb 21, 2024 | Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional p... |
| CVE-2024-1108 | HIGH | 8.2 | 0.5% | Feb 21, 2024 | The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now