2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-36656MEDIUM6.1In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (...
CVE-2024-23442MEDIUM6.1An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if th...
CVE-2024-5731MEDIUM6.8A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to cont...
CVE-2024-2023MEDIUM4.3The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi...
CVE-2024-34012MEDIUM4.4Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manage...
CVE-2024-4863MEDIUM5.4The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Si...
CVE-2024-37182MEDIUM6.1Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows ...
CVE-2024-25142MEDIUM5.5Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cac...
CVE-2024-5961MEDIUM5.3Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cros...
CVE-2024-5465MEDIUM5.5Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availa...
CVE-2024-36503MEDIUM5.5Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect ...
CVE-2024-36502MEDIUM5.5Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect a...
CVE-2024-36501MEDIUM5.5Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect ...
CVE-2024-36500MEDIUM5.5Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect se...
CVE-2024-36499MEDIUM5.5Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerabili...
CVE-2024-5994MEDIUM5.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS...
CVE-2024-5155MEDIUM6.1The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as ...
CVE-2024-4751MEDIUM4.3The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which coul...
CVE-2024-4480MEDIUM6.1The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, whic...
CVE-2024-4271MEDIUM4.6The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the a...
CVE-2024-4270MEDIUM5.4The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the aut...
CVE-2024-4005MEDIUM4.8The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-3993MEDIUM4.6The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as wel...
CVE-2024-3992MEDIUM4.8The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privil...
CVE-2024-3978MEDIUM5.4The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now