2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-10639MEDIUM4.8The Auto Prune Posts WordPress plugin before 3.0.0 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-10634MEDIUM4.3The Nokaut Offers Box WordPress plugin through 1.4.0 does not have CSRF check in place when updating its settings, which...
CVE-2024-10632MEDIUM4.8The Nokaut Offers Box WordPress plugin through 1.4.0 does not sanitize and escape some of its settings, which could allo...
CVE-2024-10631MEDIUM6.5The Countdown Timer for WordPress Block Editor WordPress plugin through 1.0.5 does not validate and escape some of its b...
CVE-2024-10504MEDIUM5.4The Contact Form, Survey, Quiz & Popup Form Builder WordPress plugin before 1.7.1 does not sanitise and escape some par...
CVE-2024-10475MEDIUM4.8The Responsive Contact Form Builder & Lead Generation Plugin WordPress plugin before 1.9.8 does not sanitise and escape ...
CVE-2024-10362MEDIUM4.8The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of...
CVE-2024-10149MEDIUM4.8The Social Slider Feed WordPress plugin before 2.2.9 does not sanitise and escape some of its settings, which could allo...
CVE-2024-10145MEDIUM4.8The Hubbub Lite WordPress plugin before 1.34.4 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-10144MEDIUM4.8The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some ...
CVE-2024-10143MEDIUM4.8The MB Custom Post Types & Custom Taxonomies WordPress plugin before 2.7.7 does not sanitise and escape some of its sett...
CVE-2024-10107MEDIUM4.8The Giveaways and Contests by RafflePress WordPress plugin before 1.12.17 does not sanitise and escape some of its sett...
CVE-2024-10076MEDIUM5.9The Jetpack WordPress plugin before 13.8, Jetpack Boost WordPress plugin before 3.4.8 use regexes in the Site Accelera...
CVE-2024-10075MEDIUM5.6The Jetpack WordPress plugin before 13.8 does not ensure that the post created by the Contact Form is only accessible t...
CVE-2024-10054MEDIUM4.8The Happyforms WordPress plugin before 1.26.3 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-10009MEDIUM4.1The Melapress File Monitor WordPress plugin before 2.1.0 does not sanitize and escape a parameter before using it in a S...
CVE-2024-0970MEDIUM5.3This User Activity Tracking and Log WordPress plugin before 4.1.4 retrieves client IP addresses from potentially untrust...
CVE-2024-56006MEDIUM5.3Missing Authorization vulnerability in Automattic Jetpack Debug Tools.This issue affects Jetpack Debug Tools: from n/a b...
CVE-2024-51666MEDIUM4.3Missing Authorization vulnerability in Tosin Oguntuyi Tours tours.This issue affects Tours: from n/a through <= 1.0.0.
CVE-2024-56427MEDIUM6.5An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200,...
CVE-2024-57096MEDIUM5.5An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
CVE-2024-45516MEDIUM6.1An issue was discovered in Zimbra Collaboration (ZCS) 9.0.0 before Patch 43, 10.0.x before 10.0.12, 10.1.x before 10.1.4...
CVE-2024-56157MEDIUM6.3iTop is an web based IT Service Management tool. Prior to versions 3.1.3 and 3.2.1, by filling malicious code in a CSV c...
CVE-2024-52601MEDIUM6.5iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, anyone with an account havi...
CVE-2024-57273MEDIUM5.4Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XS...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now