2024 CVE Vulnerabilities

39,227 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-3462MEDIUM5.4Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorizati...
CVE-2024-3461MEDIUM5.5KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application fro...
CVE-2024-3239MEDIUM5.4The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape som...
CVE-2024-3068MEDIUM4.8The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' ...
CVE-2024-35172MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.Thi...
CVE-2024-35171MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Acade...
CVE-2024-35170MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Stick...
CVE-2024-35169MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_bloc...
CVE-2024-35167MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's ...
CVE-2024-35165MEDIUM5.3Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n...
CVE-2024-35048MEDIUM4.3An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.
CVE-2024-34946MEDIUM6.5Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parame...
CVE-2024-34899MEDIUM5.4WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
CVE-2024-34828MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin:...
CVE-2024-34827MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban Tra...
CVE-2024-34825MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: fro...
CVE-2024-34823MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects A...
CVE-2024-34817MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elem...
CVE-2024-34816MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io...
CVE-2024-34814MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2...
CVE-2024-34812MEDIUM5.3Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Build...
CVE-2024-34811MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ...
CVE-2024-34749MEDIUM6.1Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remot...
CVE-2024-34709MEDIUM5.4Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens functi...
CVE-2024-34708MEDIUM4.9Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any coll...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now