2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-4248HIGH8.8A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. This issue affects the function formQo...
CVE-2024-4247HIGH8.8A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. This vulnerability affects the fu...
CVE-2024-3309MEDIUM5.4The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's...
CVE-2024-4246HIGH8.8A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). This affects the function form...
CVE-2024-3342CRITICAL9.9The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attri...
CVE-2024-4245HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is...
CVE-2024-3034LOW2.7The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13...
CVE-2024-2838MEDIUM6.4The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wo...
CVE-2024-2258MEDIUM5.4The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored ...
CVE-2024-2859HIGH7.2By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could exp...
CVE-2024-4244HIGH8.8A vulnerability classified as critical was found in Tenda W9 1.0.0.7(4456). Affected by this vulnerability is the functi...
CVE-2024-4243HIGH8.8A vulnerability classified as critical has been found in Tenda W9 1.0.0.7(4456). Affected is the function formwrlSSIDset...
CVE-2024-3052HIGH7.5Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway...
CVE-2024-3051HIGH7.5Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent...
CVE-2024-31828MEDIUM6.1Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensit...
CVE-2024-31741MEDIUM6.1Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string i...
CVE-2024-31551HIGH7.5Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete a...
CVE-2024-30804CRITICAL9.8An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbi...
CVE-2024-28322CRITICAL9.8SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allo...
CVE-2024-4242HIGH8.8A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function form...
CVE-2024-4241HIGH8.8A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the fu...
CVE-2024-4240HIGH8.8A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQ...
CVE-2024-4239HIGH8.8A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function for...
CVE-2024-32887MEDIUM5.5Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr...
CVE-2024-32883HIGH7.7MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represen...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now