2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-51419MEDIUM6.1Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibiti...
CVE-2024-51242MEDIUM6.5A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployControl...
CVE-2024-48807MEDIUM5.4Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to e...
CVE-2024-48346MEDIUM6.1xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerab...
CVE-2024-43382MEDIUM5.9Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being u...
CVE-2024-48272MEDIUM6.5D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers t...
CVE-2024-10546MEDIUM6.3A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects u...
CVE-2024-46531MEDIUM6.3phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchi...
CVE-2024-48648MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attacker...
CVE-2024-48569MEDIUM5.4Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edi...
CVE-2024-48241MEDIUM5.5An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function...
CVE-2024-31975MEDIUM4.8EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID para...
CVE-2024-31973MEDIUM5.2Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS...
CVE-2024-31972MEDIUM4.3EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary J...
CVE-2024-9110MEDIUM6.1A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform re...
CVE-2024-50344MEDIUM4.6I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browse...
CVE-2024-50353MEDIUM5.3ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files ...
CVE-2024-33626MEDIUM5.3The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure ...
CVE-2024-33603MEDIUM5.3The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenti...
CVE-2024-32946MEDIUM5.9A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitte...
CVE-2024-3935MEDIUM6.5In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridg...
CVE-2024-9388MEDIUM5.4The Black Widgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads i...
CVE-2024-50512MEDIUM5.3Generation of Error Message Containing Sensitive Information vulnerability in Posti Posti Shipping posti-shipping allows...
CVE-2024-8444MEDIUM5.4The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross...
CVE-2024-10223MEDIUM6.4The WP Team – WordPress Team Member Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plu...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now