2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-42168CRITICAL9.4HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that ...
CVE-2024-12627HIGH7.5The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne...
CVE-2024-12505MEDIUM6.4The Trackserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tsmap' shortcode in ...
CVE-2024-12472MEDIUM4.3The Post Duplicator plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.3...
CVE-2024-12404HIGH7.5The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all...
CVE-2024-12204MEDIUM5.4The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulne...
CVE-2024-11327MEDIUM6.1The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is...
CVE-2024-9188HIGH8.8Specially constructed queries cause cross platform scripting leaking administrator tokens
CVE-2024-9134HIGH8.3Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application acce...
CVE-2024-9133MEDIUM5.6A user with administrator privileges is able to retrieve authentication tokens
CVE-2024-9132CRITICAL9.8The administrator is able to configure an insecure captive portal script
CVE-2024-9131HIGH7.2A user with administrator privileges can perform command injection
CVE-2024-7142MEDIUM4.6On Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA...
CVE-2024-47520HIGH7.6A user with advanced report application access rights can perform actions for which they are not authorized
CVE-2024-47519HIGH7.1Backup uploads to ETM subject to man-in-the-middle interception
CVE-2024-47518HIGH7.6Specially constructed queries targeting ETM could discover active remote access sessions
CVE-2024-47517MEDIUM6.8Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
CVE-2024-7095MEDIUM4.3On affected platforms running Arista EOS with SNMP configured, if “snmp-server transmit max-size” is configured, under s...
CVE-2024-5872MEDIUM6.5On affected platforms running Arista EOS, a specially crafted packet with incorrect VLAN tag might be copied to CPU, whi...
CVE-2024-54998MEDIUM5.4MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter ...
CVE-2024-54997MEDIUM5.4MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field ...
CVE-2024-54996HIGH8.8MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and...
CVE-2024-54994MEDIUM6.5MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_nam...
CVE-2024-6437MEDIUM5.8On affected platforms running Arista EOS with one of the following features configured to redirect IP traffic to a next ...
CVE-2024-33299MEDIUM4.7Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the Firs...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now