2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-31281MEDIUM6.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a th...
CVE-2024-30540MEDIUM5.3Guessable CAPTCHA vulnerability in Guido VS Contact Form allows Functionality Bypass.This issue affects VS Contact Form:...
CVE-2024-30522MEDIUM5.3Authentication Bypass by Spoofing vulnerability in Stefano Lissa & The Newsletter Team Newsletter allows Functionality B...
CVE-2024-30509MEDIUM6.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Artbees SellKit allows R...
CVE-2024-30479MEDIUM5.3Authentication Bypass by Spoofing vulnerability in LionScripts IP Blocker Lite allows Functionality Bypass.This issue af...
CVE-2024-25906MEDIUM4.3Authentication Bypass by Spoofing vulnerability in WP Happy Coders Comments Like Dislike allows Functionality Bypass.Thi...
CVE-2024-25595MEDIUM5.3Authentication Bypass by Spoofing vulnerability in WPMU DEV Defender Security allows Functionality Bypass.This issue aff...
CVE-2024-24874MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in CodePeople CP Polls allow...
CVE-2024-24873MEDIUM5.3: Improper Control of Interaction Frequency vulnerability in CodePeople CP Polls allows Flooding.This issue affects CP P...
CVE-2024-24715MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidde...
CVE-2024-23522MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Strategy11 Form Builder T...
CVE-2024-35110MEDIUM5.5A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.cl...
CVE-2024-3580MEDIUM6.1The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high...
CVE-2024-3231MEDIUM6.1The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthent...
CVE-2024-34757MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderl...
CVE-2024-34575MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in deTheme Det...
CVE-2024-34567MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in GhozyLab, I...
CVE-2024-32800MEDIUM6.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Felix Moira...
CVE-2024-2744MEDIUM4.3The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow...
CVE-2024-2697MEDIUM6.5The socialdriver-framework WordPress plugin before 2024.0.0 does not validate and escape some of its shortcode attribute...
CVE-2024-3134MEDIUM5.4The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vu...
CVE-2024-4204MEDIUM4.3The Bulk Posts Editing For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
CVE-2024-3609MEDIUM4.3The ReviewX – Multi-criteria Rating & Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized deletio...
CVE-2024-2619MEDIUM5.4The Elementor Header & Footer Builder for WordPress is vulnerable to HTML Injection in all versions up to, and including...
CVE-2024-22390MEDIUM4.4Improper input validation in firmware for some Intel(R) FPGA products before version 2.9.1 may allow denial of service.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now