2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4088MEDIUM4.3The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to unauthorized modification of...
CVE-2024-2368MEDIUM4.3The Mollie Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2024-1164MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's contact form...
CVE-2024-4886MEDIUM4.3The contains an IDOR vulnerability that allows a user to comment on a private post by manipulating the ID included in t...
CVE-2024-3667MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Link To' field of mu...
CVE-2024-2087MEDIUM6.1The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form name values in a...
CVE-2024-1940MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post content in all versi...
CVE-2024-1161MEDIUM5.4The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Custom Attri...
CVE-2024-5149MEDIUM5.3The BuddyForms plugin for WordPress is vulnerable to Email Verification Bypass in all versions up to, and including, 2.8...
CVE-2024-34055MEDIUM6.5Cyrus IMAP before 3.8.3 and 3.10.x before 3.10.0-rc1 allows authenticated attackers to cause unbounded memory allocation...
CVE-2024-5483MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio...
CVE-2024-5317MEDIUM6.1The Newsletter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'np1' parameter in all versions...
CVE-2024-30889MEDIUM5.4Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execu...
CVE-2024-4220MEDIUM5.3Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumer...
CVE-2024-34364MEDIUM6.5Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror...
CVE-2024-34362MEDIUM5.9Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) ...
CVE-2024-32464MEDIUM6.1Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment includ...
CVE-2024-30528MEDIUM6.3Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a throu...
CVE-2024-34759MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhispe...
CVE-2024-35653MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi...
CVE-2024-35652MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolo...
CVE-2024-35651MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plug...
CVE-2024-35649MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pdfcrowd Sa...
CVE-2024-29004MEDIUM4.3The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web c...
CVE-2024-0756MEDIUM5.4The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 lacks validation of URLs when adding i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now