2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6588MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
CVE-2024-6555MEDIUM5.3The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to...
CVE-2024-5811MEDIUM5.4The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could ...
CVE-2024-5626MEDIUM6.1The Inline Related Posts WordPress plugin before 3.7.0 does not sanitise and escape a parameter before outputting it bac...
CVE-2024-4753MEDIUM4.8The WP Secure Maintenance WordPress plugin before 1.7 does not sanitise and escape some of its settings, which could all...
CVE-2024-3112MEDIUM4.8The Quotes and Tips by BestWebSoft WordPress plugin before 1.45 does not properly validate image files uploaded, allowin...
CVE-2024-2696MEDIUM4.8The socialdriver-framework WordPress plugin before 2024.04.30 does not sanitise and escape some of its settings, which c...
CVE-2024-2640MEDIUM5.4The Watu Quiz WordPress plugin before 3.4.1.2 does not sanitise and escape some of its settings, which could allow users...
CVE-2024-2430MEDIUM5.4The Website Content in Page or Post WordPress plugin before 2024.04.09 does not validate and escape some of its shortcod...
CVE-2024-0974MEDIUM4.8The Social Media Widget WordPress plugin before 4.0.9 does not sanitise and escape some of its settings, which could all...
CVE-2024-1375MEDIUM4.3The Event post plugin for WordPress is vulnerable to unauthorized bulk metadata update due to a missing nonce check on t...
CVE-2024-6392MEDIUM5.4The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized plugin settings modificat...
CVE-2024-6485MEDIUM6.4A security vulnerability has been discovered in bootstrap that could enable Cross-Site Scripting (XSS) attacks. The vuln...
CVE-2024-39553MEDIUM6.9An Exposure of Resource to Wrong Sphere vulnerability in the sampling service of Juniper Networks Junos OS Evolved allow...
CVE-2024-39539MEDIUM6A Missing Release of Memory after Effective Lifetime vulnerability in Juniper Networks Junos OS on MX Series allows an u...
CVE-2024-39537MEDIUM6.9An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolve...
CVE-2024-39536MEDIUM6A Missing Release of Memory after Effective Lifetime vulnerability in the Periodic Packet Management Daemon (ppmd) of Ju...
CVE-2024-39533MEDIUM6.9An Unimplemented or Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on QFX5000 Series and EX460...
CVE-2024-39532MEDIUM6.3An Insertion of Sensitive Information into Log File vulnerability in Juniper Networks Junos OS and Junos OS Evolved allo...
CVE-2024-39905MEDIUM5.3Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_chann...
CVE-2024-39528MEDIUM6A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved al...
CVE-2024-39317MEDIUM4.9Wagtail is an open source content management system built on Django. A bug in Wagtail's `parse_query_string` would resul...
CVE-2024-6035MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerabil...
CVE-2024-6528MEDIUM6.1CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c...
CVE-2024-5680MEDIUM5.5CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicio...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now