2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-32698MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HappyMonster Happy...
CVE-2024-32697MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HelloAsso allows S...
CVE-2024-32696MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Infog...
CVE-2024-32695HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Gasi Languag...
CVE-2024-32694HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interacti...
CVE-2024-32693HIGH7.6Cross-Site Request Forgery (CSRF) vulnerability in ValvePress Automatic.This issue affects Automatic: from n/a before 3....
CVE-2024-32690MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood RSS ...
CVE-2024-32418CRITICAL9.8An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the add_addon.php component.
CVE-2024-30799MEDIUM4.4An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of serv...
CVE-2024-28722MEDIUM6.3Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbit...
CVE-2024-29733LOW2.7Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate v...
CVE-2024-29217MEDIUM4.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This...
CVE-2024-4022MEDIUM5.3A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been rated a...
CVE-2024-4021MEDIUM5.3A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been declare...
CVE-2024-4020HIGH8.8A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function from...
CVE-2024-4019MEDIUM6.3A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected i...
CVE-2024-4014MEDIUM6.4The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptc...
CVE-2024-1730MEDIUM5.4The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slid...
CVE-2024-1057MEDIUM5.4The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) pl...
CVE-2024-31994MEDIUM6.5Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an a...
CVE-2024-1480HIGH7.5Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authenticatio...
CVE-2024-4018HIGH7.8Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api mo...
CVE-2024-4017HIGH7.8Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) al...
CVE-2024-32392MEDIUM4.5Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functio...
CVE-2024-32391HIGH7.3Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code vi...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now