2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-7135MEDIUM6.5The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ...
CVE-2024-6725MEDIUM5.4The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for Word...
CVE-2024-7310MEDIUM6.1A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vuln...
CVE-2024-7309MEDIUM5.4A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This af...
CVE-2024-2508MEDIUM5.3The WP Mobile Menu plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c...
CVE-2024-7303MEDIUM5.4A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. Thi...
CVE-2024-7264MEDIUM6.5libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an...
CVE-2024-7300MEDIUM5.4A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file ...
CVE-2024-7299MEDIUM5.4** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issu...
CVE-2024-6412MEDIUM6.5The HTML Forms WordPress plugin before 1.3.34 does not have CSRF checks in some places, which could allow attackers to ...
CVE-2024-6408MEDIUM5.4The Slider by 10Web WordPress plugin before 1.2.57 does not sanitise and escape its Slider Title, which could allow hig...
CVE-2024-6272MEDIUM6.1The SpiderContacts WordPress plugin through 1.1.7 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-6165MEDIUM4.8The WANotifier WordPress plugin before 2.6.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-7285MEDIUM5.4A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problemat...
CVE-2024-39947MEDIUM6.5A vulnerability has been found in Dahua products.After obtaining the ordinary user's username and password, the attacker...
CVE-2024-39945MEDIUM4.9A vulnerability has been found in Dahua products.  After obtaining the administrator's username and password, the attack...
CVE-2024-7284MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0....
CVE-2024-37281MEDIUM6.5An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a larg...
CVE-2024-5901MEDIUM5.4The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widge...
CVE-2024-5250MEDIUM5.3In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations
CVE-2024-41443MEDIUM5.5A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial ...
CVE-2024-41440MEDIUM6.2A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (D...
CVE-2024-41439MEDIUM5.5A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Den...
CVE-2024-41438MEDIUM6.2A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a De...
CVE-2024-41437MEDIUM5.5A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now