2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8526MEDIUM5.9A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when vis...
CVE-2024-45514MEDIUM5.4An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists i...
CVE-2024-45512MEDIUM5.4An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerabilit...
CVE-2024-48747MEDIUM6.8An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
CVE-2024-7130MEDIUM5.5Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Comput...
CVE-2024-53426MEDIUM6.2A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-53425MEDIUM6.2A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue oc...
CVE-2024-11089MEDIUM5.3The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2024-7016MEDIUM4.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Smarttek In...
CVE-2024-11587MEDIUM6.1A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOption...
CVE-2024-9851MEDIUM5.4The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers...
CVE-2024-9828MEDIUM4.1The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it...
CVE-2024-9768MEDIUM4.8The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allo...
CVE-2024-9600MEDIUM4.8The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high priv...
CVE-2024-9542MEDIUM4.3The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to,...
CVE-2024-9442MEDIUM5.4The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versio...
CVE-2024-9371MEDIUM6.1The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-...
CVE-2024-9111MEDIUM6.4The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versi...
CVE-2024-8157MEDIUM4.3The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which...
CVE-2024-5029MEDIUM4.8The CM Table Of Contents WordPress plugin before 1.2.4 does not have CSRF check when updating its settings, and is miss...
CVE-2024-52067MEDIUM4.9Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context valu...
CVE-2024-11596MEDIUM5.5ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or cra...
CVE-2024-11595MEDIUM5.5FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet in...
CVE-2024-11456MEDIUM6.1The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scri...
CVE-2024-11455MEDIUM6.4The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-ma...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now