2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7574MEDIUM6.1The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5...
CVE-2024-7512MEDIUM4.8Concrete CMS versions 9.0.0 through 9.3.2 are affected by a stored XSS vulnerability in Board instances. A rogue adminis...
CVE-2024-7416MEDIUM5.3The Reveal Template plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.7...
CVE-2024-7414MEDIUM5.3The PDF Builder for WPForms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includ...
CVE-2024-7413MEDIUM5.3The Obfuscate Email plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.8...
CVE-2024-7412MEDIUM5.3The No Update Nag plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.1...
CVE-2024-7410MEDIUM5.3The My Custom CSS PHP & ADS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and includ...
CVE-2024-7408MEDIUM6.5This vulnerability exists in Airveda Air Quality Monitor PM2.5 PM10 due to transmission of sensitive information in plai...
CVE-2024-7382MEDIUM5.3The Linkify Text plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.9.1....
CVE-2024-6759MEDIUM5.3When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separa...
CVE-2024-6758MEDIUM6.5Improper Privilege Management in Sprecher Automation SPRECON-E below version 8.71j allows a remote attacker with low pri...
CVE-2024-6691MEDIUM4The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPr...
CVE-2024-6640MEDIUM6.3In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Reques...
CVE-2024-6562MEDIUM5.3The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all ver...
CVE-2024-6158MEDIUM4.8The Category Posts Widget WordPress plugin before 4.9.17, term-and-category-based-posts-widget WordPress plugin before 4...
CVE-2024-6136MEDIUM5.4The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not have CSRF checks in some places, which could all...
CVE-2024-6134MEDIUM5.4The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin...
CVE-2024-6133MEDIUM6.5The wp-cart-for-digital-products WordPress plugin before 8.5.6 does not sanitise and escape a parameter before outputtin...
CVE-2024-5801MEDIUM5.3Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise ...
CVE-2024-4360MEDIUM5.4The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-4359MEDIUM6.5The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for W...
CVE-2024-4350MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in RSS Displayer when user input is s...
CVE-2024-43168MEDIUM4.8DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, ...
CVE-2024-42367MEDIUM4.8aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions on the 3.10 branch prior to ...
CVE-2024-42165MEDIUM5.4Insufficiently random values for generating activation token in FIWARE Keyrock <= 8.4 allow attackers to activate accoun...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now