2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10683MEDIUM6.1The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to ...
CVE-2024-8756MEDIUM5.3The Quform - WordPress Form Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions...
CVE-2024-10814MEDIUM6.4The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2...
CVE-2024-10770MEDIUM4.3The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 vi...
CVE-2024-10669MEDIUM4.3The Countdown Timer block – Display the event's date into a timer. plugin for WordPress is vulnerable to Informatio...
CVE-2024-10667MEDIUM4.3The Content Slider Block plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including...
CVE-2024-9226MEDIUM6.1The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflecte...
CVE-2024-10693MEDIUM4.3The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inclu...
CVE-2024-9775MEDIUM4.8The Anih - Creative Agency WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via admin se...
CVE-2024-9270MEDIUM6.4The Lenxel Core for Lenxel(LNX) LMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploa...
CVE-2024-9262MEDIUM6.5The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to Insecure Direct Ob...
CVE-2024-8960MEDIUM5.4The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ...
CVE-2024-10779MEDIUM4.3The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-10588MEDIUM4.3The Debug Tool plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on th...
CVE-2024-52314MEDIUM6.9A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to ...
CVE-2024-52313MEDIUM5.3An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the pa...
CVE-2024-52312MEDIUM5.4Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to per...
CVE-2024-52311MEDIUM6.3Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticat...
CVE-2024-10953MEDIUM5.3An authenticated data.all user is able to perform mutating UPDATE operations on persisted Notification records in data.a...
CVE-2024-52001MEDIUM4.3Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access for...
CVE-2024-52000MEDIUM6.1Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site ...
CVE-2024-35427MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser....
CVE-2024-35425MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_funct...
CVE-2024-35424MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser....
CVE-2024-35421MEDIUM5.5vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now