2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3945MEDIUM4.3The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3....
CVE-2024-3943MEDIUM4.3The WP To Do plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3....
CVE-2024-3277MEDIUM5The Yumpu ePaper publishing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap...
CVE-2024-5223MEDIUM6.4The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-3269MEDIUM5.4The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capabil...
CVE-2024-3190MEDIUM4.6The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cros...
CVE-2024-3063MEDIUM5.4The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the output of 'tags' adde...
CVE-2024-2253MEDIUM6.4The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via URL values ...
CVE-2024-3726MEDIUM6.4The Login Logout Register Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'llrml...
CVE-2024-35221MEDIUM4.3Rubygems.org is the Ruby community's gem hosting service. A Gem publisher can cause a Remote DoS when publishing a Gem. ...
CVE-2024-35512MEDIUM5.3hmq v1.5.5 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can trigger a bro...
CVE-2024-35284MEDIUM5.4A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthen...
CVE-2024-35283MEDIUM6.1A vulnerability in the Ignite component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticat...
CVE-2024-35200MEDIUM5.3When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX w...
CVE-2024-34161MEDIUM5.3When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maxi...
CVE-2024-32760MEDIUM6.5When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 encoder instructions can c...
CVE-2024-31079MEDIUM4.8When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX w...
CVE-2024-28974MEDIUM6.5Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privile...
CVE-2024-36375MEDIUM5.3In JetBrains TeamCity before 2024.03.2 technical information regarding TeamCity server could be exposed
CVE-2024-36374MEDIUM5.4In JetBrains TeamCity before 2024.03.2 stored XSS via build step settings was possible
CVE-2024-36373MEDIUM5.4In JetBrains TeamCity before 2024.03.2 several stored XSS in untrusted builds settings were possible
CVE-2024-36372MEDIUM6.1In JetBrains TeamCity before 2023.05.6 reflected XSS on the subscriptions page was possible
CVE-2024-36371MEDIUM5.4In JetBrains TeamCity before 2023.05.6, 2023.11.5 stored XSS in Commit status publisher was possible
CVE-2024-36370MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via OAuth connection settings was pos...
CVE-2024-36369MEDIUM5.4In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 stored XSS via issue tracker integration was pos...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now