2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-52917MEDIUM6.5Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received ...
CVE-2024-52913MEDIUM5.3In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because ...
CVE-2024-38828MEDIUM5.3Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
CVE-2024-11306MEDIUM6.9A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th...
CVE-2024-11305MEDIUM6.3A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability ...
CVE-2024-52386MEDIUM5.3Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-11094MEDIUM5.3The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-10592MEDIUM6.4The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a...
CVE-2024-10614MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili...
CVE-2024-9938MEDIUM6.1The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...
CVE-2024-9850MEDIUM6.4The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all version...
CVE-2024-9615MEDIUM6.1The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho...
CVE-2024-9386MEDIUM6.4The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-8873MEDIUM6.1The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th...
CVE-2024-6628MEDIUM4.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site R...
CVE-2024-11118MEDIUM5.3The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-11092MEDIUM6.4The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versi...
CVE-2024-11085MEDIUM5.4The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch...
CVE-2024-10884MEDIUM6.1The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-10883MEDIUM6.1The SimpleForm – Contact form made simple plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th...
CVE-2024-10875MEDIUM6.1The Gallery Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_Query_...
CVE-2024-10533MEDIUM4.3The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check...
CVE-2024-10262MEDIUM6.3The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
CVE-2024-10147MEDIUM6.4The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versio...
CVE-2024-10017MEDIUM6.4The PJW Mime Config plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now