2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-26157MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26156MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26155HIGH8.6All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 expose clear text credentials in the web portal....
CVE-2024-26154MEDIUM6.1All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting...
CVE-2024-26153HIGH7.4All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.9.19 are vulnerable to cross-site request forgery (C...
CVE-2024-50967MEDIUM6.5The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability....
CVE-2024-13503CRITICAL9.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299...
CVE-2024-13502CRITICAL9.3Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire...
CVE-2024-12703HIGH8.5CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity an...
CVE-2024-12142HIGH8.8CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause information di...
CVE-2024-10498MEDIUM6.9CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow a...
CVE-2024-10497HIGH8.8CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker t...
CVE-2024-13378MEDIUM5.4The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter i...
CVE-2024-13377HIGH7.2The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versi...
CVE-2024-12476HIGH8.4CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclos...
CVE-2024-12399HIGH7.1CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists t...
CVE-2024-12370MEDIUM5.3The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-11425HIGH8.7CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product whe...
CVE-2024-11139MEDIUM4.6CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow l...
CVE-2024-13386MEDIUM6.4The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all ...
CVE-2024-13367MEDIUM6.5The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_do...
CVE-2024-13366MEDIUM6.1The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versio...
CVE-2024-12637MEDIUM5.3The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-12598MEDIUM6.4The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ p...
CVE-2024-12508MEDIUM6.4The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'g...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now