2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-29977MEDIUM4.3Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are ...
CVE-2024-6923MEDIUM5.5There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email ...
CVE-2024-2455MEDIUM5.4The Element Pack - Addon for Elementor Page Builder WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-...
CVE-2024-6346MEDIUM5.4The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t...
CVE-2024-38490MEDIUM4.4Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta...
CVE-2024-38489MEDIUM4.4Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attack...
CVE-2024-38481MEDIUM4.4Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attac...
CVE-2024-25948MEDIUM4.4Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local atta...
CVE-2024-7302MEDIUM5.4The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi...
CVE-2024-5678MEDIUM4.7Zohocorp ManageEngine Applications Manager versions 170900 and below are vulnerable to the authenticated admin-only SQL ...
CVE-2024-5331MEDIUM4.3The Breakdance plugin for WordPress is vulnerable to unauthorized access of data in all versions up to, and including, 1...
CVE-2024-5330MEDIUM5.4The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the breakdance_css_file_paths_cache...
CVE-2024-25947MEDIUM4.4Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local atta...
CVE-2024-6496MEDIUM6.5The Light Poll WordPress plugin through 1.0.0 does not have CSRF checks when deleting polls, which could allow attackers...
CVE-2024-4090MEDIUM4.8The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin ...
CVE-2024-2872MEDIUM4.8The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c...
CVE-2024-2843MEDIUM6.5The WooCommerce Customers Manager WordPress plugin before 30.1 does not have CSRF checks in some places, which could all...
CVE-2024-1747MEDIUM6.5The WooCommerce Customers Manager WordPress plugin before 30.2 does not have authorisation and CSRF in various AJAX acti...
CVE-2024-7343MEDIUM6.1A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknow...
CVE-2024-7342MEDIUM6.1A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part ...
CVE-2024-2090MEDIUM6.4The Remote Content Shortcode plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, an...
CVE-2024-7339MEDIUM5.3A vulnerability has been found in TVT DVR TD-2104TS-CL, DVR TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM) and AVISION...
CVE-2024-39607MEDIUM6.8OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the...
CVE-2024-34021MEDIUM6.8Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted...
CVE-2024-7330MEDIUM6.3A vulnerability has been found in YouDianCMS 7 and classified as critical. Affected by this vulnerability is the functio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now