2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-38832MEDIUM6.4VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to vi...
CVE-2024-8899MEDIUM4.3The Jeg Elementor Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2024-50377MEDIUM6.5A CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-...
CVE-2024-50376MEDIUM5.2A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting...
CVE-2024-10579MEDIUM4.3The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized access ...
CVE-2024-10308MEDIUM5.4The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's JKit - Countdow...
CVE-2024-11032MEDIUM6.1The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg with...
CVE-2024-9170MEDIUM4.8The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_produ...
CVE-2024-11192MEDIUM6.4The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
CVE-2024-11119MEDIUM6.4The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' sh...
CVE-2024-11091MEDIUM6.4The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2024-8772MEDIUM4.351l3nc3, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API managedoverlayimages.cgi was vulnerable ...
CVE-2024-6831MEDIUM4.4Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program has found that it is possible to edit and/or remove vie...
CVE-2024-34162MEDIUM5.3The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But co...
CVE-2024-33616MEDIUM5.3Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrat...
CVE-2024-32151MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-29978MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-29146MEDIUM5.9User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved ...
CVE-2024-28955MEDIUM5.9Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the ...
CVE-2024-11202MEDIUM6.1Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in v...
CVE-2024-6749MEDIUM6.3Seth Fogie, member of the AXIS Camera Station Pro Bug Bounty Program, has found that the Incident report feature may exp...
CVE-2024-6476MEDIUM4.2Gee-netics, member of the AXIS Camera Station Pro Bug Bounty Program has found that it is possible for a non-admin user ...
CVE-2024-11002MEDIUM6.3The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via the inpost_gallery_get_sh...
CVE-2024-10857MEDIUM6.5The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to...
CVE-2024-10471MEDIUM4.8The Everest Forms WordPress plugin before 3.0.4.2 does not sanitise and escape some of its settings, which could allow ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now