2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-12434MEDIUM5.3The SureMembers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin...
CVE-2024-10563MEDIUM5.4The WooCommerce Cart Count Shortcode WordPress plugin before 1.1.0 does not validate and escape some of its shortcode at...
CVE-2024-27246MEDIUM6.5Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n...
CVE-2024-27245MEDIUM6.5Buffer overflow in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via ...
CVE-2024-27239MEDIUM6.5Use after free in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct a denial of service via n...
CVE-2024-45426MEDIUM6.5Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclos...
CVE-2024-45425MEDIUM6.5Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure v...
CVE-2024-45417MEDIUM5.5Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privile...
CVE-2024-36259MEDIUM6.5Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attac...
CVE-2024-11955MEDIUM6.1A vulnerability was found in GLPI up to 10.0.17. It has been declared as problematic. Affected by this vulnerability is ...
CVE-2024-54444MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Elemento...
CVE-2024-34036MEDIUM4.3An issue was discovered in O-RAN Near Realtime RIC I-Release. To exploit this vulnerability, an attacker can disrupt the...
CVE-2024-34035MEDIUM5.7An issue was discovered in O-RAN Near Realtime RIC H-Release. To trigger the crashing of the e2mgr, an adversary must fl...
CVE-2024-34034MEDIUM5.7An issue was discovered in FlexRIC 2.0.0. It crashes during a Subscription Request denial-of-service (DoS) attack, trigg...
CVE-2024-13695MEDIUM5.4The Enfold theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.0.9 ...
CVE-2024-13693MEDIUM5.3The Enfold theme for WordPress is vulnerable to unauthorized access of data due to a missing capability check in avia-ex...
CVE-2024-13494MEDIUM4.3The WordPress File Upload plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in...
CVE-2024-57685MEDIUM5.3An issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.
CVE-2024-53543MEDIUM5.4NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 was discovered to contain a SQL injection vulnerability...
CVE-2024-53542MEDIUM6.5Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Tim...
CVE-2024-57608MEDIUM6.5An issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.
CVE-2024-57026MEDIUM6.1TawkTo Widget Version <= 1.3.7 is vulnerable to Cross Site Scripting (XSS) due to processing user input in a way that al...
CVE-2024-5174MEDIUM5.3A flaw in Gliffy results in broken authentication through the reset functionality of the application.
CVE-2024-13822MEDIUM6.1The Photo Contest | Competition | Video Contest WordPress plugin through 2.8.1 does not sanitise and escape a parameter...
CVE-2024-13605MEDIUM4.8The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now