2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-5691MEDIUM4.7By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if click...
CVE-2024-5690MEDIUM4.3By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were fun...
CVE-2024-5689MEDIUM4.3In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button ...
CVE-2024-5687MEDIUM5.3If a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new ...
CVE-2024-2462MEDIUM6.8Allow attackers to intercept or falsify data exchanges between the client and the server
CVE-2024-2461MEDIUM6.9If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccess...
CVE-2024-35212MEDIUM6.9A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected a...
CVE-2024-35211MEDIUM6.8A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w...
CVE-2024-35210MEDIUM5.1A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w...
CVE-2024-35209MEDIUM6.9A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w...
CVE-2024-35208MEDIUM5.5A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected w...
CVE-2024-5829MEDIUM5.3A vulnerability classified as problematic was found in smallweigit Avue up to 3.4.4. Affected by this vulnerability is a...
CVE-2024-35685MEDIUM5.3Missing Authorization vulnerability in Anders Norén Radcliffe 2.This issue affects Radcliffe 2: from n/a through 2.0.17.
CVE-2024-34813MEDIUM5.3Missing Authorization vulnerability in Moreconvert Team MC Woocommerce Wishlist smart-wishlist-for-more-convert.This iss...
CVE-2024-5584MEDIUM6.4The WordPress Online Booking and Scheduling Plugin – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2024-34824MEDIUM6.3Missing Authorization vulnerability in ThemeBoy SportsPress – Sports Club & League Manager.This issue affects SportsPres...
CVE-2024-24704MEDIUM6.3Missing Authorization vulnerability in AddonMaster Load More Anything.This issue affects Load More Anything: from n/a th...
CVE-2024-5531MEDIUM6.4The Ocean Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flickr widget in all versions ...
CVE-2024-4319MEDIUM5.3The Advanced Contact form 7 DB plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabi...
CVE-2024-3723MEDIUM5.3The Advanced Contact form 7 DB plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up t...
CVE-2024-31402MEDIUM4.3Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker to delete ...
CVE-2024-31399MEDIUM6.5Excessive platform resource consumption within a loop issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerabili...
CVE-2024-31398MEDIUM4.3Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability i...
CVE-2024-31397MEDIUM4.9Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a u...
CVE-2024-5530MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) pl...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now