2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-4274MEDIUM4.3The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation...
CVE-2024-4273MEDIUM5.4The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_proper...
CVE-2024-4057MEDIUM6.1The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.37 does not validate and escape some of its bloc...
CVE-2024-3230MEDIUM6.4The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-at...
CVE-2024-3031MEDIUM4.4The Fluid Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v...
CVE-2024-2470MEDIUM5.4The Simple Ajax Chat WordPress plugin before 20240412 does not sanitise and escape some of its settings, which could al...
CVE-2024-2382MEDIUM5.3The Authorize.net Payment Gateway For WooCommerce plugin for WordPress is vulnerable to payment bypass in all versions u...
CVE-2024-1718MEDIUM5.3The Claudio Sanches – Checkout Cielo for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ...
CVE-2024-1717MEDIUM4.3The Admin Notices Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ...
CVE-2024-0757MEDIUM5.4The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file e...
CVE-2024-3888MEDIUM6.4The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button shortcode ...
CVE-2024-29976MEDIUM6.5** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the command “show_allsessions” in Zyx...
CVE-2024-29975MEDIUM6.7** UNSUPPORTED WHEN ASSIGNED ** The improper privilege management vulnerability in the SUID executable binary in Zyxel N...
CVE-2024-34051MEDIUM4.6A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0....
CVE-2024-36674MEDIUM6.1LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.
CVE-2024-36124MEDIUM5.3iq80 Snappy is a compression/decompression library. When uncompressing certain data, Snappy tries to read outside the bo...
CVE-2024-36123MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its ...
CVE-2024-36729MEDIUM6.3TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows...
CVE-2024-35632MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks. Integration for Contact Form 7 and Constant Contact.This i...
CVE-2024-34770MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup ...
CVE-2024-34769MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in cyclonethem...
CVE-2024-34767MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in HasThemes S...
CVE-2024-34766MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic ...
CVE-2024-34385MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooC...
CVE-2024-34803MEDIUM4.3Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now