2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7689MEDIUM4.3The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation ...
CVE-2024-7688MEDIUM6.5The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make...
CVE-2024-7687MEDIUM4.3The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well ...
CVE-2024-6910MEDIUM4.8The EventON WordPress plugin before 2.2.17 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2024-5561MEDIUM4.8The Popup Maker WordPress plugin before 1.19.1 does not sanitise and escape some of its settings, which could allow hig...
CVE-2024-45625MEDIUM6.1Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an...
CVE-2024-8586MEDIUM6.1WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulner...
CVE-2024-8585MEDIUM6.5Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowi...
CVE-2024-8583MEDIUM5.4A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It ha...
CVE-2024-8582MEDIUM6.1A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected ...
CVE-2024-42342MEDIUM4.3Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
CVE-2024-42341MEDIUM6.1Loway - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CVE-2024-8572MEDIUM6.1A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affect...
CVE-2024-8571MEDIUM5.3A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as ...
CVE-2024-6925MEDIUM4.3The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could ...
CVE-2024-6859MEDIUM5.4The WP MultiTasking WordPress plugin through 0.1.12 does not validate and escape some of its shortcode attributes befor...
CVE-2024-6856MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which...
CVE-2024-6855MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could all...
CVE-2024-6853MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could ...
CVE-2024-6852MEDIUM4.3The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which...
CVE-2024-8566MEDIUM6.1A vulnerability classified as problematic was found in code-projects Online Shop Store 1.0. This vulnerability affects u...
CVE-2024-8563MEDIUM6.1A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown...
CVE-2024-8562MEDIUM6.1A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some u...
CVE-2024-42022MEDIUM5.3An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
CVE-2024-42021MEDIUM6.5An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now