2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-54997MEDIUM5.4MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field ...
CVE-2024-54994MEDIUM6.5MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_nam...
CVE-2024-6437MEDIUM5.8On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next ...
CVE-2024-33299MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the Firs...
CVE-2024-33298MEDIUM6.1Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code v...
CVE-2024-33297MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the camp...
CVE-2024-54910MEDIUM4.7Hasleo Backup Suite Free v4.9.4 and before is vulnerable to Insecure Permissions via the File recovery function.
CVE-2024-6880MEDIUM6.9During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping ...
CVE-2024-57222MEDIUM6.3Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc...
CVE-2024-54687MEDIUM6.1Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndS...
CVE-2024-57214MEDIUM6.3TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parame...
CVE-2024-57213MEDIUM6.3TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd para...
CVE-2024-57212MEDIUM5.1TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode paramet...
CVE-2024-54849MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitiv...
CVE-2024-54847MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access ...
CVE-2024-54846MEDIUM5.9An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data o...
CVE-2024-50807MEDIUM6.1Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf e...
CVE-2024-57823MEDIUM5.5In Raptor RDF Syntax Library through 2.0.16, there is an integer underflow when normalizing a URI with the turtle parser...
CVE-2024-57822MEDIUM5.5In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads...
CVE-2024-13318MEDIUM5.3The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check...
CVE-2024-13183MEDIUM5.4The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_tag’ paramet...
CVE-2024-12606MEDIUM4.3The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-12473MEDIUM6.5The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin Ch...
CVE-2024-56377MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject...
CVE-2024-56376MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now