2024 CVE Vulnerabilities

39,219 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-11308MEDIUM5.5The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore th...
CVE-2024-52926MEDIUM6.5Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
CVE-2024-52922MEDIUM6.5In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes...
CVE-2024-52921MEDIUM5.3In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.
CVE-2024-52919MEDIUM6.5Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via ...
CVE-2024-52918MEDIUM6.5Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and ap...
CVE-2024-52917MEDIUM6.5Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received ...
CVE-2024-52913MEDIUM5.3In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because ...
CVE-2024-38828MEDIUM5.3Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.
CVE-2024-11306MEDIUM6.9A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. Th...
CVE-2024-11305MEDIUM6.3A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability ...
CVE-2024-52386MEDIUM5.3Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2024-11094MEDIUM5.3The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2024-10592MEDIUM6.4The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in a...
CVE-2024-10614MEDIUM4.3The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capabili...
CVE-2024-9938MEDIUM6.1The Bounce Handler MailPoet 3 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parame...
CVE-2024-9850MEDIUM6.4The SVG Case Study plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all version...
CVE-2024-9615MEDIUM6.1The BulkPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho...
CVE-2024-9386MEDIUM6.4The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-S...
CVE-2024-8873MEDIUM6.1The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to th...
CVE-2024-6628MEDIUM4.3The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to Cross-Site R...
CVE-2024-11118MEDIUM5.3The 404 Error Monitor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ...
CVE-2024-11092MEDIUM6.4The SVGPlus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versi...
CVE-2024-11085MEDIUM5.4The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability ch...
CVE-2024-10884MEDIUM6.1The SimpleForm Contact Form Submissions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now