2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-12466MEDIUM6.1The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all v...
CVE-2024-12203MEDIUM4.4The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in ...
CVE-2024-13333HIGH7.5The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validati...
CVE-2024-11146MEDIUM6.3TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-...
CVE-2024-10799MEDIUM6.5The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via th...
CVE-2024-13434MEDIUM6.1The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramete...
CVE-2024-13401MEDIUM6.4The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_pay...
CVE-2024-13398MEDIUM6.4The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for...
CVE-2024-51462MEDIUM5.3IBM QRadar WinCollect Agent 10.0.0 through 10.1.12 could allow a remote attacker to inject XML data into parameter value...
CVE-2024-52363HIGH7.5IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker ...
CVE-2024-34579HIGH8.5Fuji Electric Alpha5 SMART is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbi...
CVE-2024-57785MEDIUM4.9Zenitel AlphaWeb XE v11.2.3.10 was discovered to contain a local file inclusion vulnerability via the component amc_uplo...
CVE-2024-57784MEDIUM5.5An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a direct...
CVE-2024-57704HIGH8.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi...
CVE-2024-57703CRITICAL9.8Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability. Affected by this vulnerability is the function setSchedWifi...
CVE-2024-56144MEDIUM5.4librenms is a community-based GPL-licensed network monitoring system. Affected versions are subject to a stored XSS on t...
CVE-2024-53553CRITICAL9.1An issue in OPEXUS FOIAXPRESS PUBLIC ACCESS LINK v11.1.0 allows attackers to bypass authentication via crafted web reque...
CVE-2024-40514MEDIUM4.6Insecure Permissions vulnerability in themesebrand Chatvia v.5.3.2 allows a remote attacker to escalate privileges via t...
CVE-2024-40513MEDIUM4.6An issue in themesebrand Chatvia v.5.3.2 allows a remote attacker to execute arbitrary code via the User profile Upload ...
CVE-2024-55511HIGH7.8A null pointer dereference vulnerability in Macrium Reflect prior to 8.1.8017 allows a local attacker to cause a system ...
CVE-2024-54660HIGH8.7A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala be...
CVE-2024-48460MEDIUM4.3An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the S...
CVE-2024-46450HIGH8.1Incorrect access control in Tenda AC1200 Smart Dual-Band WiFi Router Model AC6 v2.0 Firmware v15.03.06.50 allows attacke...
CVE-2024-57583CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the for...
CVE-2024-57582CRITICAL9.8Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the startIP parameter in the formSetPPTPServer fu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now