2024 CVE Vulnerabilities

39,247 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-1956MEDIUM6.1The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in t...
CVE-2024-1752MEDIUM6.1The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high ...
CVE-2024-1589MEDIUM6.1The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which co...
CVE-2024-1588MEDIUM6.8The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which co...
CVE-2024-1292MEDIUM4.7The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back i...
CVE-2024-23658MEDIUM4.4In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service wi...
CVE-2024-28744HIGH8.8The password is empty in the initial configuration of ACERA 9010-08 firmware v02.04 and earlier, and ACERA 9010-24 firmw...
CVE-2024-3437HIGH7.2A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. This issue affe...
CVE-2024-3436HIGH7.2A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnera...
CVE-2024-3434MEDIUM5.4A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability ...
CVE-2024-3433MEDIUM5.4A vulnerability classified as problematic has been found in PuneethReddyHC Event Management 1.0. Affected is an unknown ...
CVE-2024-3432HIGH8.8A vulnerability was found in PuneethReddyHC Event Management 1.0. It has been rated as critical. This issue affects some...
CVE-2024-3431HIGH8.8A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability affects unknown code of...
CVE-2024-3430LOW2.4A vulnerability was found in QKSMS up to 3.9.4 on Android. It has been classified as problematic. This affects an unknow...
CVE-2024-31951MEDIUM6.5In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash i...
CVE-2024-31950MEDIUM6.5In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets...
CVE-2024-31949MEDIUM6.5In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability bec...
CVE-2024-31948MEDIUM6.5In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the ...
CVE-2024-3428MEDIUM6.1A vulnerability has been found in SourceCodester Online Courseware 1.0 and classified as problematic. This vulnerability...
CVE-2024-31349MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch MailMunc...
CVE-2024-31348MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testim...
CVE-2024-31346MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksmarket Gradi...
CVE-2024-31345CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Pos...
CVE-2024-31344MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Phpbits Creative S...
CVE-2024-31308HIGH7.2Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue affects WP Import Export ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now