2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-49237MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in ahmeti Ahmeti Wp Timeline ahmeti-wp-timeline allows Stored XSS.This i...
CVE-2024-49229MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arifnezami Better ...
CVE-2024-49223MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in shibulijack CJ Change Howdy cj-change-howdy allows Cross Site Request...
CVE-2024-49221MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in julian.weinert cSlider cslider allows Cross Site Request Forgery.This...
CVE-2024-49220MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Nikel Cookie Scanner cookie-scanner allows Cross Site Request Forgery...
CVE-2024-9683MEDIUM5.3A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is prov...
CVE-2024-47459MEDIUM5.5Substance3D - Sampler versions 4.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead ...
CVE-2024-49580MEDIUM5.3In JetBrains Ktor before 2.3.13 improper caching in HttpCache Plugin could lead to response information disclosure
CVE-2024-49579MEDIUM6.1In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized...
CVE-2024-48046MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in supsystic Contact ...
CVE-2024-48037MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Contact Form Widget new-contact-form-widget allows Cross Si...
CVE-2024-48036MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT B...
CVE-2024-48031MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in sumitsurai Featured Posts with Multiple Custom Groups (FPMCG) feature...
CVE-2024-48025MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dogrow Simple Base...
CVE-2024-48022MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SysBasics S...
CVE-2024-48047MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Razon Komar Pal Linked Variation for WooCommerce linked-variation-for...
CVE-2024-48038MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in tuxlog wp-Monalisa wp-monalisa.This issue affects wp-Monalisa: from n...
CVE-2024-9898MEDIUM5.4The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dd-parallax shortc...
CVE-2024-45713MEDIUM4.4SolarWinds Kiwi CatTools is susceptible to a sensitive data disclosure vulnerability when a non-default setting has been...
CVE-2024-8920MEDIUM6.4The Fonto – Custom Web Fonts Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo...
CVE-2024-49392MEDIUM4.8Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acro...
CVE-2024-49386MEDIUM5.7Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows...
CVE-2024-9951MEDIUM6.1The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' paramete...
CVE-2024-3187MEDIUM5.9This issue tracks two CWE-416 Use After Free (UAF) and one CWE-415 Double Free vulnerabilities in Goahead versions <= 6....
CVE-2024-3186MEDIUM5.3CWE-476 NULL Pointer Dereference vulnerability in the evalExpr() function of GoAhead Web Server (version <= 6.0.0) when ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now