2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-37046MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2024-37045MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2024-37043MEDIUM4.9A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul...
CVE-2024-37042MEDIUM4.9A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploite...
CVE-2024-32770MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability co...
CVE-2024-32769MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability co...
CVE-2024-32768MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability co...
CVE-2024-32767MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability co...
CVE-2024-10863MEDIUM5.1: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This is...
CVE-2024-49054MEDIUM4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-51766MEDIUM6.5A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability ...
CVE-2024-41781MEDIUM5.9IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 ...
CVE-2024-7882MEDIUM6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Desi...
CVE-2024-8929MEDIUM5.8In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the clie...
CVE-2024-9422MEDIUM6.6The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently valida...
CVE-2024-8735MEDIUM6.1The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use...
CVE-2024-11381MEDIUM6.4The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' short...
CVE-2024-11355MEDIUM4.3The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data ...
CVE-2024-11225MEDIUM6.1The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripti...
CVE-2024-10666MEDIUM4.3The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all ve...
CVE-2024-10034MEDIUM5.5The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native ga...
CVE-2024-38296MEDIUM4.4Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain ...
CVE-2024-47142MEDIUM5.5AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue wi...
CVE-2024-45837MEDIUM5.4Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A networ...
CVE-2024-39290MEDIUM6.5Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticate...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now