2024 CVE Vulnerabilities

39,235 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-30203MEDIUM5.5In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
CVE-2024-28183MEDIUM5.7ESP-IDF is the development framework for Espressif SoCs supported on Windows, Linux and macOS. A Time-of-Check to Time-o...
CVE-2024-25175MEDIUM6.1An issue in Kickdler before v1.107.0 allows attackers to provide an XSS payload via a HTTP response splitting attack.
CVE-2024-28435MEDIUM5.4The CRM platform Twenty version 0.3.0 is vulnerable to SSRF via file upload.
CVE-2024-2864MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify ...
CVE-2024-30187MEDIUM5.3Anope before 2.0.15 does not prevent resetting the password of a suspended account.
CVE-2024-29216MEDIUM6.1Exposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOC...
CVE-2024-29009MEDIUM6.1Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker...
CVE-2024-21865MEDIUM6.5HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated at...
CVE-2024-1564MEDIUM4.3The wp-schema-pro WordPress plugin before 2.7.16 does not validate post access allowing a contributor user to access cus...
CVE-2024-1232MEDIUM4.8The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac...
CVE-2024-1231MEDIUM6.8The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attac...
CVE-2024-29034MEDIUM6.1CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-...
CVE-2024-30161MEDIUM6.5In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly ...
CVE-2024-24840MEDIUM5.4Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor ...
CVE-2024-24835MEDIUM6.5Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.
CVE-2024-2832MEDIUM6.1A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects ...
CVE-2024-2326MEDIUM4.3The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable t...
CVE-2024-1049MEDIUM5.4The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2024-2688MEDIUM5.4The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-2468MEDIUM5.4The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gute...
CVE-2024-2202MEDIUM5.4The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image wi...
CVE-2024-2131MEDIUM5.4The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox...
CVE-2024-1697MEDIUM5.4The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
CVE-2024-29057MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now