2024 CVE Vulnerabilities

39,236 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-22459MEDIUM6.5Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper a...
CVE-2024-1954MEDIUM6.3The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in a...
CVE-2024-1791MEDIUM5.4The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all...
CVE-2024-1566MEDIUM6.5The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-1516MEDIUM5.3The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability ...
CVE-2024-1476MEDIUM5.3The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposu...
CVE-2024-1368MEDIUM5.3The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ...
CVE-2024-1136MEDIUM5.3The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an impr...
CVE-2024-0975MEDIUM5.3The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-0786MEDIUM6.5The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress...
CVE-2024-0768MEDIUM4.3The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2024-0767MEDIUM4.3The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2024-0766MEDIUM4.3The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification...
CVE-2024-0682MEDIUM5.3The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5...
CVE-2024-0680MEDIUM5.3The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and incl...
CVE-2024-0433MEDIUM4.3The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-0432MEDIUM4.3The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-0431MEDIUM4.3The Gestpay for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...
CVE-2024-27913MEDIUM6.5ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service ...
CVE-2024-1943MEDIUM4.3The Yuki theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including 1.3.14. Th...
CVE-2024-1568MEDIUM6.4The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and...
CVE-2024-1388MEDIUM4.3The Yuki theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
CVE-2024-22723MEDIUM4.9Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attack...
CVE-2024-0550MEDIUM6.5A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relativ...
CVE-2024-1932MEDIUM4.8Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now