2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32679MEDIUM5.3Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a...
CVE-2024-31804MEDIUM6.7An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privile...
CVE-2024-28130HIGH7.5An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality of OFFIS D...
CVE-2024-2477MEDIUM5.4The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an up...
CVE-2024-28627HIGH7.5An issue in Flipsnack v.18/03/2024 allows a local attacker to obtain sensitive information via the reader.gz.js file.
CVE-2024-3911MEDIUM6.5An unauthenticated remote attacker can deceive users into performing unintended actions due to improper restriction of r...
CVE-2024-30800MEDIUM5.6PX4 Autopilot v.1.14 allows an attacker to fly the drone into no-fly zones by breaching the geofence using flaws in the ...
CVE-2024-26922MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping o...
CVE-2024-3491MEDIUM6.4The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug...
CVE-2024-3732MEDIUM5.4The GeoDirectory – WordPress Business Directory Plugin, or Classified Directory plugin for WordPress is vulnerable to St...
CVE-2024-3665MEDIUM5.4The Rank Math SEO with AI SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's H...
CVE-2024-3185MEDIUM6.8 A key used in logging.json does not follow the least privilege principle by default and is exposed to local users in th...
CVE-2024-0900MEDIUM4.3The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding...
CVE-2024-3664MEDIUM4.3The Quick Featured Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab...
CVE-2024-4031MEDIUM4.4Unquoted Search Path or Element vulnerability in Logitech MEVO WEBCAM APP on Windows allows Local Execution of Code.
CVE-2024-3889MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-2799MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image...
CVE-2024-2798MEDIUM6.4The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2024-2493HIGH7.5Session Hijacking vulnerability in Hitachi Ops Center Analyzer.This issue affects Hitachi Ops Center Analyzer: from 10.0...
CVE-2024-31857MEDIUM5.4Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote a...
CVE-2024-31077HIGH7.2Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenti...
CVE-2024-28890MEDIUM5.3Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerabil...
CVE-2024-21511CRITICAL9.8Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of t...
CVE-2024-2760MEDIUM5.5Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IO...
CVE-2024-1241MEDIUM5.5Watchdog Antivirus v1.6.415 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002014 IOCTL code o...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now