2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-32452MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WP EasyCart.This issue affects WP EasyCart: from n/a through 5.5.19.
CVE-2024-32451MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in wpWax Legal Pages.This issue affects Legal Pages: from n/a through 1....
CVE-2024-32450MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team WpTravelly.This issue affects WpTravelly: from n/a th...
CVE-2024-32449MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in MagniGenie RestroPress.This issue affects RestroPress: from n/a throu...
CVE-2024-32448MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in VideoYield.Com Ads.Txt Admin.This issue affects Ads.Txt Admin: from n...
CVE-2024-32447MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in AWP Classifieds Team AWP Classifieds.This issue affects AWP Classifie...
CVE-2024-32446MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet Sys...
CVE-2024-32082MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Kamlesh Parmar Sync Post With Other Site sync-post-with-other-site al...
CVE-2024-32454MEDIUM4.4Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wap...
CVE-2024-32453MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POEditor allows St...
CVE-2024-32429MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPChill Remove Foo...
CVE-2024-32428MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moss Web Works MWW...
CVE-2024-32149MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Jobs for...
CVE-2024-32147MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Form Plugin Team -...
CVE-2024-32145MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PineWise WP Google...
CVE-2024-32140MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in libsyn Libsyn Publ...
CVE-2024-32138MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short...
CVE-2024-32133MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenie...
CVE-2024-32079MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Ad...
CVE-2024-32489MEDIUM6.1TCPDF before 6.7.4 mishandles calls that use HTML syntax.
CVE-2024-2858MEDIUM4.8The Simple Buttons Creator WordPress plugin through 1.04 does not have CSRF checks in some places, which could allow att...
CVE-2024-2857MEDIUM6.1The Simple Buttons Creator WordPress plugin through 1.04 does not have any authorisation as well as CSRF in its add butt...
CVE-2024-2836MEDIUM4.8The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape ...
CVE-2024-1849MEDIUM5.4The WP Customer Reviews WordPress plugin before 3.7.1 does not validate a parameter allowing contributor and above users...
CVE-2024-1846MEDIUM5.4The Responsive Tabs WordPress plugin before 4.0.7 does not validate and escape some of its shortcode attributes before o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now