2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11694MEDIUM6.1Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS thr...
CVE-2024-11692MEDIUM4.3An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possib...
CVE-2024-47250MEDIUM5Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI advertising report could lead to ou...
CVE-2024-47249MEDIUM5Improper Validation of Array Index vulnerability in Apache NimBLE. Lack of input validation for HCI events from control...
CVE-2024-47248MEDIUM6.3Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. Specially crafte...
CVE-2024-38834MEDIUM4.8VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cl...
CVE-2024-38833MEDIUM5.4VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to em...
CVE-2024-38832MEDIUM6.4VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to vi...
CVE-2024-8899MEDIUM4.3The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-50377MEDIUM6.5A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-...
CVE-2024-50376MEDIUM5.2A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting...
CVE-2024-10579MEDIUM4.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access ...
CVE-2024-10308MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow...
CVE-2024-11032MEDIUM6.1The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with...
CVE-2024-9170MEDIUM4.8The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ...
CVE-2024-11192MEDIUM6.4The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11119MEDIUM6.4The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh...
CVE-2024-11091MEDIUM6.4The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-8772MEDIUM4.351l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable ...
CVE-2024-6831MEDIUM4.4Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove vie...
CVE-2024-34162MEDIUM5.3The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But co...
CVE-2024-33616MEDIUM5.3Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrat...
CVE-2024-32151MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-29978MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-29146MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now