2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-34566MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk...
CVE-2024-34565MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debug Info allows ...
CVE-2024-34564MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Inc. Cou...
CVE-2024-34563MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoldAddons Gold Ad...
CVE-2024-34562MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Ad...
CVE-2024-4281MEDIUM5.4The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' short...
CVE-2024-4135MEDIUM5.4The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and inclu...
CVE-2024-34572MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePrix Fancy El...
CVE-2024-34571MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalay...
CVE-2024-4438HIGH7.5The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487...
CVE-2024-4437HIGH7.5The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue oc...
CVE-2024-4436HIGH7.5The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue oc...
CVE-2024-34574MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker...
CVE-2024-34573MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pootlepress Pootle...
CVE-2024-3494MEDIUM6.4The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_co...
CVE-2024-1076MEDIUM6.5The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it...
CVE-2024-32674MEDIUM5.4Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is e...
CVE-2024-22266MEDIUM6.5 VMware Avi Load Balancer contains an information disclosure vulnerability. A malicious actor with access to the system ...
CVE-2024-22264HIGH7.2VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious actor with admin privileges on VMwar...
CVE-2024-4418MEDIUM6.2A race condition leading to a stack use-after-free flaw was found in libvirt. Due to a bad assumption in the virNetClien...
CVE-2024-4393CRITICAL9.8The Social Connect plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.2. Th...
CVE-2024-4162MEDIUM4.4A buffer error in Panasonic KW Watcher versions 1.00 through 2.83 may allow attackers malicious read access to memory.
CVE-2024-2860HIGH7.8The PostgreSQL implementation in Brocade SANnav versions before 2.3.0a is vulnerable to an incorrect local authenticatio...
CVE-2024-2746HIGH8.8Incomplete fix for CVE-2024-1929 The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon accepted arbitrary confi...
CVE-2024-1930MEDIUM6.5No Limit on Number of Open Sessions / Bad Session Close Behaviour in dnf5daemon-server before 5.1.17 allows a malicious...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now