2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-13669MEDIUM6.1The CalendApp WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13634MEDIUM6.1The Post Sync WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the pag...
CVE-2024-13630MEDIUM6.1The NewsTicker WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the pa...
CVE-2024-13629MEDIUM6.1The pushBIZ WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page...
CVE-2024-13628MEDIUM6.1The WP Pricing Table WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in ...
CVE-2024-13560MEDIUM4.3The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versi...
CVE-2024-13113MEDIUM5.9The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when output...
CVE-2024-12737MEDIUM6.1The WP BASE Booking of Appointments, Services and Events WordPress plugin before 5.0.0 does not sanitise and escape a pa...
CVE-2024-12434MEDIUM5.3The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2024-10563MEDIUM5.4The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode at...
CVE-2024-27246MEDIUM6.5Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n...
CVE-2024-27245MEDIUM6.5Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via ...
CVE-2024-27239MEDIUM6.5Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n...
CVE-2024-45426MEDIUM6.5Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclos...
CVE-2024-45425MEDIUM6.5Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure v...
CVE-2024-45417MEDIUM5.5Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privile...
CVE-2024-36259MEDIUM6.5Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac...
CVE-2024-11955MEDIUM6.1A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is ...
CVE-2024-54444MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...
CVE-2024-34036MEDIUM4.3An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the...
CVE-2024-34035MEDIUM5.7An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must fl...
CVE-2024-34034MEDIUM5.7An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, trigg...
CVE-2024-13695MEDIUM5.4The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 ...
CVE-2024-13693MEDIUM5.3The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-ex...
CVE-2024-13494MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now