2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-27969MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Enhanced Free D...
CVE-2024-27966MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ExpressTech Quiz A...
CVE-2024-25922MEDIUM5.4Missing Authorization vulnerability in Peach Payments Peach Payments Gateway.This issue affects Peach Payments Gateway: ...
CVE-2024-25908MEDIUM4.3Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5...
CVE-2024-25907MEDIUM5.4Missing Authorization vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5...
CVE-2024-24883MEDIUM4.3Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Ad...
CVE-2024-24850MEDIUM5.3Missing Authorization vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Po...
CVE-2024-3613MEDIUM5.4A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been rated as problematic. Affected ...
CVE-2024-3612MEDIUM5.4A vulnerability was found in SourceCodester Warehouse Management System 1.0. It has been declared as problematic. Affect...
CVE-2024-32001MEDIUM4.3SpiceDB is a graph database purpose-built for storing and evaluating access control data. Use of a relation of the form:...
CVE-2024-29902MEDIUM5.9Cosign provides code signing and transparency for containers and binaries. Prior to version 2.2.4, a remote image with a...
CVE-2024-31995MEDIUM4.3`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0....
CVE-2024-31985MEDIUM5.4XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1...
CVE-2024-29460MEDIUM6.6An issue in PX4 Autopilot v.1.14.0 allows an attacker to manipulate the flight path allowing for crashes of the drone vi...
CVE-2024-1481MEDIUM5.3A flaw was found in FreeIPA. This issue may allow a remote attacker to craft a HTTP request with parameters that can be ...
CVE-2024-31939MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Soflyy Import any XML or CSV File to WordPress.This issue affects Imp...
CVE-2024-29502MEDIUM6.5An issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC p...
CVE-2024-3516MEDIUM6.5Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit ...
CVE-2024-3515MEDIUM6.5Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap co...
CVE-2024-31464MEDIUM4.9XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9...
CVE-2024-31386MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Hidekazu Ishikawa X-T9, Hidekazu Ishikawa Lightning, themeinwp Defaul...
CVE-2024-28345MEDIUM5.5An issue discovered in Sipwise C5 NGCP Dashboard below mr11.5.1 allows a low privileged user to access the Journal endpo...
CVE-2024-31944MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Octolize WooCommerce UPS Shipping – Live Rates and Access Points.This...
CVE-2024-31943MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Octolize USPS Shipping for WooCommerce – Live Rates.This issue affect...
CVE-2024-31242MEDIUM5.3Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now