2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-27906MEDIUM5.9Apache Airflow, versions before 2.8.2, has a vulnerability that allows authenticated users to view DAG code and import e...
CVE-2024-1953MEDIUM4.3Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, 9.3.0, and 9.4.x before 9.4.2 fail to limit the number of ro...
CVE-2024-1952MEDIUM4.3Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemer...
CVE-2024-1942MEDIUM4.3Mattermost versions 8.1.x before 8.1.9, 9.2.x before 9.2.5, and 9.3.0 fail to sanitize the metadata on posts containing ...
CVE-2024-1888MEDIUM4.3Mattermost fails to check the "invite_guest" permission when inviting guests of other teams to a team, allowing a member...
CVE-2024-24988MEDIUM6.5Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to s...
CVE-2024-23493MEDIUM6.5Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch de...
CVE-2024-23488MEDIUM4.3Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members...
CVE-2024-1887MEDIUM4.3Mattermost fails to check if compliance export is enabled when fetching posts of public channels allowing a user that is...
CVE-2024-25594MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Savvy Wordpress De...
CVE-2024-1978MEDIUM5.5The Friends plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.8....
CVE-2024-25098MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pascal Bajorat PB ...
CVE-2024-25094MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paul Jura & Nicola...
CVE-2024-25093MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Milan Petrovic GD ...
CVE-2024-23501MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Eboo...
CVE-2024-21752MEDIUM6.1Cross-Site Request Forgery (CSRF) vulnerability in Ernest Marcinko Ajax Search Lite allows Reflected XSS.This issue affe...
CVE-2024-1977MEDIUM4.8The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist...
CVE-2024-1976MEDIUM4.3The Marketing Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2024-1437MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in José Fernandez Ads...
CVE-2024-1434MEDIUM4.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jordy Meow Media A...
CVE-2024-1341MEDIUM5.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe s...
CVE-2024-0689MEDIUM4.8The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versio...
CVE-2024-27517MEDIUM5.4Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code afte...
CVE-2024-27092MEDIUM5.4Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad...
CVE-2024-27083MEDIUM6.1Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerabil...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now