2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-54997 | MEDIUM | 5.4 | 0.3% | Jan 10, 2025 | MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field ... |
| CVE-2024-54994 | MEDIUM | 6.5 | 0.3% | Jan 10, 2025 | MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_nam... |
| CVE-2024-6437 | MEDIUM | 5.8 | 0.5% | Jan 10, 2025 | On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next ... |
| CVE-2024-33299 | MEDIUM | 4.7 | 1.1% | Jan 10, 2025 | Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the Firs... |
| CVE-2024-33298 | MEDIUM | 6.1 | 0.8% | Jan 10, 2025 | Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code v... |
| CVE-2024-33297 | MEDIUM | 4.7 | 1.1% | Jan 10, 2025 | Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the camp... |
| CVE-2024-54910 | MEDIUM | 4.7 | 0.4% | Jan 10, 2025 | Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function. |
| CVE-2024-6880 | MEDIUM | 6.9 | 0.5% | Jan 10, 2025 | During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping ... |
| CVE-2024-57222 | MEDIUM | 6.3 | 0.8% | Jan 10, 2025 | Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc... |
| CVE-2024-54687 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndS... |
| CVE-2024-57214 | MEDIUM | 6.3 | 0.7% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parame... |
| CVE-2024-57213 | MEDIUM | 6.3 | 0.7% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd para... |
| CVE-2024-57212 | MEDIUM | 5.1 | 0.7% | Jan 10, 2025 | TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode paramet... |
| CVE-2024-54849 | MEDIUM | 5.9 | 0.4% | Jan 10, 2025 | An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitiv... |
| CVE-2024-54847 | MEDIUM | 5.9 | 0.4% | Jan 10, 2025 | An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access ... |
| CVE-2024-54846 | MEDIUM | 5.9 | 0.4% | Jan 10, 2025 | An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data o... |
| CVE-2024-50807 | MEDIUM | 6.1 | 0.3% | Jan 10, 2025 | Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf e... |
| CVE-2024-57823 | MEDIUM | 5.5 | 0.3% | Jan 10, 2025 | In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser... |
| CVE-2024-57822 | MEDIUM | 5.5 | 0.3% | Jan 10, 2025 | In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads... |
| CVE-2024-13318 | MEDIUM | 5.3 | 0.3% | Jan 10, 2025 | The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check... |
| CVE-2024-13183 | MEDIUM | 5.4 | 0.5% | Jan 10, 2025 | The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ paramet... |
| CVE-2024-12606 | MEDIUM | 4.3 | 0.3% | Jan 10, 2025 | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch... |
| CVE-2024-12473 | MEDIUM | 6.5 | 0.5% | Jan 10, 2025 | The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch... |
| CVE-2024-56377 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject... |
| CVE-2024-56376 | MEDIUM | 5.4 | 0.4% | Jan 9, 2025 | A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now