2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-41884MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker ...
CVE-2024-41883MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR . An attacker...
CVE-2024-41882MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can...
CVE-2024-12622MEDIUM6.4The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w...
CVE-2024-12405MEDIUM6.1The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in ...
CVE-2024-12210MEDIUM4.3The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-12100MEDIUM6.1The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-12096MEDIUM6.1The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it b...
CVE-2024-12034MEDIUM5.3The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, ...
CVE-2024-11885MEDIUM6.4The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte...
CVE-2024-12710MEDIUM6.1The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi...
CVE-2024-12617MEDIUM5.4The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c...
CVE-2024-12518MEDIUM6.4The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho...
CVE-2024-12507MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2024-12266MEDIUM6.5The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due...
CVE-2024-9427MEDIUM5.4A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link ...
CVE-2024-56362MEDIUM5.5Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext...
CVE-2024-53276MEDIUM6.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, a...
CVE-2024-53275MEDIUM5.3Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. In 1.15.0 and earlier, t...
CVE-2024-56364MEDIUM5.4SimpleXLSX is software for parsing and retrieving data from Excel XLSx files. Starting in 1.0.12 and ending in 1.1.13, w...
CVE-2024-23945MEDIUM5.9Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authentici...
CVE-2024-11230MEDIUM5.4The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘size’ p...
CVE-2024-12901MEDIUM6.9A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown funct...
CVE-2024-52321MEDIUM5.9Multiple SHARP routers contain an improper authentication vulnerability in the configuration backup function. The produc...
CVE-2024-47864MEDIUM5.3home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now