2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6340MEDIUM5.4The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Coun...
CVE-2024-6263MEDIUM5.4The WP Lightbox 2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver...
CVE-2024-4482MEDIUM5.4The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre...
CVE-2024-2375MEDIUM5.4The WPQA Builder WordPress plugin before 6.1.1 does not sanitise and escape some of its Slider settings, which could all...
CVE-2024-2235MEDIUM4.3The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use...
CVE-2024-2234MEDIUM5.4The Himer WordPress theme before 2.1.1 does not sanitise and escape some of its Post settings, which could allow high pr...
CVE-2024-2233MEDIUM4.3The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make log...
CVE-2024-2231MEDIUM6.5The allows any authenticated user to join a private group due to a missing authorization check on a function
CVE-2024-2040MEDIUM4.3The Himer WordPress theme before 2.1.1 does not have CSRF checks in some places, which could allow attackers to make use...
CVE-2024-4543MEDIUM4.3The Snippet Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2024-39920MEDIUM4.3The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of...
CVE-2024-32673MEDIUM6.7Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segme...
CVE-2024-39326MEDIUM4.4SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectnam...
CVE-2024-39325MEDIUM5.3aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 202...
CVE-2024-39322MEDIUM5.5aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 202...
CVE-2024-39315MEDIUM6.5Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pome...
CVE-2024-6381MEDIUM5.3The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function ...
CVE-2024-39891MEDIUM5.3In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoin...
CVE-2024-5866MEDIUM4.3Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner...
CVE-2024-5865MEDIUM6.5Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner...
CVE-2024-39316MEDIUM6.5Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression De...
CVE-2024-25087MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue sc...
CVE-2024-22105MEDIUM5.5Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue sc...
CVE-2024-32932MEDIUM6.8Under certain circumstances the web interface users credentials may be recovered by an authenticated user.
CVE-2024-22104MEDIUM5.5Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now