2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-35728MEDIUM5.3Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Them...
CVE-2024-35712MEDIUM4.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jordy Meow Database Clea...
CVE-2024-35680MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in YITHEMES YITH WooCommerce...
CVE-2024-35474MEDIUM6.5A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose ...
CVE-2024-31613MEDIUM5.4BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
CVE-2024-36531MEDIUM5.7nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admi...
CVE-2024-36406MEDIUM5.4SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and ...
CVE-2024-5786MEDIUM6.5Cross-Site Request Forgery vulnerability in Comtrend router WLD71-T1_v2.0.201820, affecting the GRG-4280us version. This...
CVE-2024-4746MEDIUM6.3Missing Authorization vulnerability in netgsm Netgsm netgsm allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2024-4745MEDIUM6.3Missing Authorization vulnerability in RafflePress Giveaways and Contests by RafflePress.This issue affects Giveaways an...
CVE-2024-2408MEDIUM5.9The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is ...
CVE-2024-5458MEDIUM5.3In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering funct...
CVE-2024-35748MEDIUM5.3Missing Authorization vulnerability in OPMC WooCommerce Dropshipping.This issue affects WooCommerce Dropshipping: from n...
CVE-2024-32704MEDIUM6.5Missing Authorization vulnerability in reputeinfosystems ARForms arforms.This issue affects ARForms: from n/a through <=...
CVE-2024-31347MEDIUM4.3Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a ...
CVE-2024-31307MEDIUM6.3Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: ...
CVE-2024-32725MEDIUM5.3Missing Authorization vulnerability in Saleswonder Team: Tobias 5 Stars Rating Funnel 5-stars-rating-funnel.This issue a...
CVE-2024-37535MEDIUM4.4GNOME VTE before 0.76.3 allows an attacker to cause a denial of service (memory consumption) via a window resize escape ...
CVE-2024-32727MEDIUM5.3Missing Authorization vulnerability in Rometheme RomethemeForm For Elementor.This issue affects RomethemeForm For Elemen...
CVE-2024-32821MEDIUM4.3Missing Authorization vulnerability in TotalSuite Total Poll Lite.This issue affects Total Poll Lite: from n/a through 4...
CVE-2024-32820MEDIUM5.3Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Soc...
CVE-2024-32814MEDIUM5.3Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pic...
CVE-2024-32813MEDIUM5.3Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/...
CVE-2024-32811MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.Th...
CVE-2024-32805MEDIUM6.5Missing Authorization vulnerability in Social Snap.This issue affects Social Snap: from n/a through 1.3.5.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now