2024 CVE Vulnerabilities
39,227 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-3462 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorizati... |
| CVE-2024-3461 | MEDIUM | 5.5 | 0.3% | May 14, 2024 | KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application fro... |
| CVE-2024-3239 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.0.2 does not validate and escape som... |
| CVE-2024-3068 | MEDIUM | 4.8 | 0.6% | May 14, 2024 | The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cfs[fields][*][name]' ... |
| CVE-2024-35172 | MEDIUM | 4.4 | 0.4% | May 14, 2024 | Server-Side Request Forgery (SSRF) vulnerability in ShortPixel ShortPixel Adaptive Images shortpixel-adaptive-images.Thi... |
| CVE-2024-35171 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Academy LMS academy.This issue affects Acade... |
| CVE-2024-35170 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hidden Depth Stick... |
| CVE-2024-35169 | MEDIUM | 5.9 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in all_bootstrap_bloc... |
| CVE-2024-35167 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EnvoThemes Envo's ... |
| CVE-2024-35165 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gutenify.This issue affects Gutenify: from n... |
| CVE-2024-35048 | MEDIUM | 4.3 | 0.4% | May 14, 2024 | An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password. |
| CVE-2024-34946 | MEDIUM | 6.5 | 0.7% | May 14, 2024 | Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parame... |
| CVE-2024-34899 | MEDIUM | 5.4 | 0.5% | May 14, 2024 | WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2024-34828 | MEDIUM | 4.3 | 0.3% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin:... |
| CVE-2024-34827 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs, Razvan Mocanu, Madalin Ungureanu, Cristophor Hurduban Tra... |
| CVE-2024-34825 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Warfare Plugins Social Warfare.This issue affects Social Warfare: fro... |
| CVE-2024-34823 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Kiboko Labs Arigato Autoresponder and Newsletter.This issue affects A... |
| CVE-2024-34817 | MEDIUM | 4.3 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Integration for Pipedrive and Contact Form 7, WPForms, Elem... |
| CVE-2024-34816 | MEDIUM | 5.4 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Revmakx WPCal.Io – Easy Meeting Scheduler.This issue affects WPCal.Io... |
| CVE-2024-34814 | MEDIUM | 5.4 | 0.2% | May 14, 2024 | Cross-Site Request Forgery (CSRF) vulnerability in Unyson Unyson unyson.This issue affects Unyson: from n/a through <= 2... |
| CVE-2024-34812 | MEDIUM | 5.3 | 0.6% | May 14, 2024 | Insertion of Sensitive Information Into Sent Data vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Build... |
| CVE-2024-34811 | MEDIUM | 4.8 | 0.4% | May 14, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS ... |
| CVE-2024-34749 | MEDIUM | 6.1 | 0.7% | May 14, 2024 | Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remot... |
| CVE-2024-34709 | MEDIUM | 5.4 | 0.4% | May 14, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.0, session tokens functi... |
| CVE-2024-34708 | MEDIUM | 4.9 | 0.8% | May 14, 2024 | Directus is a real-time API and App dashboard for managing SQL database content. A user with permission to view any coll... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now