2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11934MEDIUM6.4The Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce plugin for WordPress is vulnerable to Stored Cr...
CVE-2024-11899MEDIUM6.4The Slider Pro Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sliderpro' short...
CVE-2024-11777MEDIUM6.4The Sell Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sell_media_search_for...
CVE-2024-11437MEDIUM4.9The Timeline Designer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, a...
CVE-2024-54764MEDIUM6.5An access control issue in the component /login/hostinfo2.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensit...
CVE-2024-54763MEDIUM6.5An access control issue in the component /login/hostinfo.cgi of ipTIME A2004 v12.17.0 allows attackers to obtain sensiti...
CVE-2024-53936MEDIUM6.3The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any applicati...
CVE-2024-53935MEDIUM6.5The com.callos14.callscreen.colorphone (aka iCall OS17 - Color Phone Flash) application through 4.3 for Android enables ...
CVE-2024-53933MEDIUM6.3The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Andr...
CVE-2024-51741MEDIUM4.4Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may creat...
CVE-2024-55075MEDIUM5.3Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not sh...
CVE-2024-55408MEDIUM5.3An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality uti...
CVE-2024-46209MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attacke...
CVE-2024-35498MEDIUM6.1A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via...
CVE-2024-55626MEDIUM5.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr...
CVE-2024-46073MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is...
CVE-2024-56769MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value i...
CVE-2024-56768MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP ...
CVE-2024-56767MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_xdmac: avoid null_prt_deref in at_xdm...
CVE-2024-56763MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_writ...
CVE-2024-56761MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: x86/fred: Clear WFE in missing-ENDBRANCH #CPs An i...
CVE-2024-56760MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Handle lack of irqdomain gracefully Alexa...
CVE-2024-56758MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: check folio mapping after unlock in relocate...
CVE-2024-56757MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow w...
CVE-2024-47475MEDIUM5.5Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerab...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now