2024 CVE Vulnerabilities

39,228 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32826MEDIUM5.3Missing Authorization vulnerability in Vektor,Inc. VK Block Patterns.This issue affects VK Block Patterns: from n/a thro...
CVE-2024-3682MEDIUM5.3The WP STAGING and WP STAGING Pro plugins for WordPress are vulnerable to Sensitive Information Exposure in versions up ...
CVE-2024-4183MEDIUM6.5Mattermost versions 8.1.x before 8.1.12, 9.6.x before 9.6.1, 9.5.x before 9.5.3, 9.4.x before 9.4.5 fail to limit the nu...
CVE-2024-4182MEDIUM4.3Mattermost versions 9.6.0, 9.5.x before 9.5.3, 9.4.x before 9.4.5, and 8.1.x before 8.1.12 fail to handle JSON parsing e...
CVE-2024-32046MEDIUM4.3Mattermost versions 9.6.x <= 9.6.0, 9.5.x <= 9.5.2, 9.4.x <= 9.4.4 and 8.1.x <= 8.1.11 fail to remove detailed error mes...
CVE-2024-22091MEDIUM6.5Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a requ...
CVE-2024-3890MEDIUM5.4The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Calendly widget...
CVE-2024-3678MEDIUM5.3The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure...
CVE-2024-33650MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Cryout Creations Serious Slider.This issue affects Serious Slider: fr...
CVE-2024-33642MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in EkoJR Advanced Pos...
CVE-2024-33639MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAl...
CVE-2024-33638MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in Brijesh Kothari Smart Maintenance Mode.This issue affects Smart Maint...
CVE-2024-33598MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Twinpictures Annua...
CVE-2024-2920MEDIUM5.3The WP-Members Membership Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and i...
CVE-2024-3188MEDIUM6.3The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.1.0 does not validate and escape some of its sh...
CVE-2024-3060MEDIUM4.5The ENL Newsletter WordPress plugin through 1.0.1 does not sanitize and escape a parameter before using it in a SQL stat...
CVE-2024-3059MEDIUM5.7The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF checks in some places, which could allow attackers ...
CVE-2024-3058MEDIUM5.4The ENL Newsletter WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation a...
CVE-2024-3048MEDIUM5.5The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leadin...
CVE-2024-2908MEDIUM4.3The Call Now Button WordPress plugin before 1.4.7 does not sanitise and escape some of its settings, which could allow ...
CVE-2024-2837MEDIUM5.4The WP Chat App WordPress plugin before 3.6.4 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-2603MEDIUM6.3The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a...
CVE-2024-2439MEDIUM4.8The Salon booking system WordPress plugin through 9.6.5 does not sanitise and escape some of its settings, which could a...
CVE-2024-2429MEDIUM4.3The Salon booking system WordPress plugin through 9.6.5 does not have CSRF check in place when updating its settings, wh...
CVE-2024-2310MEDIUM5.9The WP Google Review Slider WordPress plugin before 13.6 does not sanitise and escape some of its settings, which could ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now