2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-0613MEDIUM6.1The Delete Custom Fields plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc...
CVE-2024-4433MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr Digital Simple ...
CVE-2024-32359MEDIUM6.9An RBAC authorization risk in Carina v0.13.0 and earlier allows local attackers to execute arbitrary code through design...
CVE-2024-31966MEDIUM6.2A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-31965MEDIUM4.2A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-31963MEDIUM6.4A vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3....
CVE-2024-4029MEDIUM4.1A vulnerability was found in Wildfly’s management interface. Due to the lack of limitation of sockets for the management...
CVE-2024-4128MEDIUM4.3This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint th...
CVE-2024-34148MEDIUM6.8Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 ...
CVE-2024-34147MEDIUM4.3Jenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file...
CVE-2024-34146MEDIUM6.5Jenkins Git server Plugin 114.v068a_c7cc2574 and earlier does not perform a permission check for read access to a Git re...
CVE-2024-34061MEDIUM4.3changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification se...
CVE-2024-33305MEDIUM6.1SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter ...
CVE-2024-33302MEDIUM5.3SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add ...
CVE-2024-23461MEDIUM5.5An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade pr...
CVE-2024-33944MEDIUM6.5Missing Authorization vulnerability in Kestrel WooCommerce AWeber Newsletter Subscription.This issue affects WooCommerce...
CVE-2024-3005MEDIUM6.4The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
CVE-2024-33930MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ILLID Share This Image.This issue affects Share Thi...
CVE-2024-33922MEDIUM5.3Insertion of Sensitive Information into Log File vulnerability in Jordy Meow WP Media Cleaner.This issue affects WP Medi...
CVE-2024-32638MEDIUM6.3Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache APISIX when using `forwa...
CVE-2024-3883MEDIUM5.4The 3D FlipBook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Bookmark URL field in all vers...
CVE-2024-3280MEDIUM6.4The Follow Us Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpsite_follow_us...
CVE-2024-3490MEDIUM5.4The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wprm-recipe-round...
CVE-2024-3481MEDIUM5.2The Counter Box WordPress plugin before 1.2.4 does not have CSRF checks in some bulk actions, which could allow attacke...
CVE-2024-3478MEDIUM6.1The Herd Effects WordPress plugin before 5.2.7 does not have CSRF checks in some bulk actions, which could allow attack...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now