2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8056MEDIUM6.1The MM-Breaking News WordPress plugin through 0.7.9 does not escape the $_SERVER['REQUEST_URI'] parameter before outputt...
CVE-2024-8054MEDIUM6.1The MM-Breaking News WordPress plugin through 0.7.9 does not have CSRF check in some places, and is missing sanitisation...
CVE-2024-7862MEDIUM6.5The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in place when updating its...
CVE-2024-7861MEDIUM6.1The Misiek Paypal WordPress plugin through 1.1.20090324 does not have CSRF check in some places, and is missing sanitisa...
CVE-2024-7860MEDIUM6.1The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitis...
CVE-2024-7859MEDIUM6.5The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could...
CVE-2024-7822MEDIUM6.1The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2024-7820MEDIUM6.5The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could ...
CVE-2024-7818MEDIUM6.1The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisati...
CVE-2024-7817MEDIUM6.5The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attack...
CVE-2024-7816MEDIUM6.1The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well...
CVE-2024-6887MEDIUM4.8The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Give...
CVE-2024-6019MEDIUM6.1The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could...
CVE-2024-6018MEDIUM6.1The Music Request Manager WordPress plugin through 1.3 does not escape the $_SERVER['REQUEST_URI'] parameter before outp...
CVE-2024-6017MEDIUM6.1The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places, and is missing sanitisat...
CVE-2024-5799MEDIUM4.8The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which cou...
CVE-2024-3163MEDIUM4.3The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which ...
CVE-2024-38222MEDIUM6.5Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2024-8708MEDIUM6.1A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. T...
CVE-2024-8707MEDIUM5.3A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. Thi...
CVE-2024-8706MEDIUM6.5A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function ...
CVE-2024-8705MEDIUM6.3A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System ...
CVE-2024-8694MEDIUM5.1A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function u...
CVE-2024-8693MEDIUM5.1A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is s...
CVE-2024-8690MEDIUM4.4A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with W...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now