2024 CVE Vulnerabilities

39,221 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-50212MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: lib: alloc_tag_module_unload must wait for pending ...
CVE-2024-51787MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quomodosoft Elemen...
CVE-2024-51786MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bestweblayout Real...
CVE-2024-51785MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in Nks Responsive Filterable Portfolio responsive-filterable-portfolio ...
CVE-2024-10876MEDIUM6.1The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul...
CVE-2024-10688MEDIUM4.3The Attesa Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.2 ...
CVE-2024-10683MEDIUM6.1The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to ...
CVE-2024-8756MEDIUM5.3The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2024-10814MEDIUM6.4The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2...
CVE-2024-10770MEDIUM4.3The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi...
CVE-2024-10669MEDIUM4.3The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informatio...
CVE-2024-10667MEDIUM4.3The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including...
CVE-2024-9226MEDIUM6.1The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflecte...
CVE-2024-10693MEDIUM4.3The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu...
CVE-2024-9775MEDIUM4.8The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se...
CVE-2024-9270MEDIUM6.4The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploa...
CVE-2024-9262MEDIUM6.5The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2024-8960MEDIUM5.4The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ...
CVE-2024-10779MEDIUM4.3The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-10588MEDIUM4.3The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-52314MEDIUM6.9A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to ...
CVE-2024-52313MEDIUM5.3An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the pa...
CVE-2024-52312MEDIUM5.4Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to per...
CVE-2024-52311MEDIUM6.3Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticat...
CVE-2024-10953MEDIUM5.3An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.a...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now