2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41697MEDIUM6.1Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CVE-2024-25009MEDIUM6.5Ericsson Packet Core Controller (PCC) contains a vulnerability in Access and Mobility Management Function (AMF) where im...
CVE-2024-7054MEDIUM5.4The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress...
CVE-2024-38808MEDIUM4.3In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a speci...
CVE-2024-5576MEDIUM5.4The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carouse...
CVE-2024-6864MEDIUM5.4The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute...
CVE-2024-7782MEDIUM6.5The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-7775MEDIUM4.8The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-6575MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-5763MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-7948MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Accounts Manager App 1.0. This vulnerability affec...
CVE-2024-7945MEDIUM5.4A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been declared as problematic. A...
CVE-2024-7850MEDIUM6.1The BP Profile Search plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-5941MEDIUM5.4The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access and dele...
CVE-2024-5940MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2024-5939MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data ...
CVE-2024-7942MEDIUM5.4A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerabilit...
CVE-2024-7929MEDIUM6.1A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects...
CVE-2024-4785MEDIUM6.5BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
CVE-2024-35539MEDIUM6.5Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil...
CVE-2024-35538MEDIUM5.3Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP ...
CVE-2024-43326MEDIUM5.4Missing Authorization vulnerability in Jamie Bergen Plugin Notes Plus allows Accessing Functionality Not Properly Constr...
CVE-2024-43317MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Metagauss U...
CVE-2024-23729MEDIUM6.1The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute ...
CVE-2024-43281MEDIUM5.3Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Element...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now