2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-50624MEDIUM5.9ispdbservice.cpp in KDE Kmail before 6.2.0 allows man-in-the-middle attackers to trigger use of an attacker-controlled m...
CVE-2024-10433MEDIUM6.1A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affecte...
CVE-2024-50615MEDIUM6.5TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp...
CVE-2024-50614MEDIUM6.5TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XM...
CVE-2024-50613MEDIUM6.5libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encod...
CVE-2024-50612MEDIUM5.5libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
CVE-2024-10419MEDIUM6.1A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected ...
CVE-2024-10414MEDIUM4.8A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an...
CVE-2024-10412MEDIUM5.4A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerabilit...
CVE-2024-50602MEDIUM5.9An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_Stop...
CVE-2024-10117MEDIUM5.4The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcf_donate short...
CVE-2024-9116MEDIUM6.4The Monkee-Boy Essentials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-10357MEDIUM4.3The Clever Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up ...
CVE-2024-9967MEDIUM5.4The WP show more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's show_more shortcode ...
CVE-2024-9853MEDIUM6.4The ID-SK Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-9642MEDIUM6.4The Editor Custom Color Palette plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-10092MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-9456MEDIUM6.4The WP Awesome Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi...
CVE-2024-8870MEDIUM6.1The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Reflected Cross-Si...
CVE-2024-9626MEDIUM4.3The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missin...
CVE-2024-9613MEDIUM6.1The FormFacade – WordPress plugin for Google Forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting ...
CVE-2024-9462MEDIUM4.8The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-9454MEDIUM6.4The PriPre plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to,...
CVE-2024-10091MEDIUM5.4The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Compari...
CVE-2024-48239MEDIUM4.8An issue was discovered in WTCMS 1.0. In the plupload method in \AssetController.class.php, the app parameters aren't pr...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now