2024 CVE Vulnerabilities

39,223 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9628MEDIUM6.5The WPS Telegram Chat plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a ...
CVE-2024-47158MEDIUM5.4N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary co...
CVE-2024-10342MEDIUM5.4The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in ver...
CVE-2024-10341MEDIUM6.5The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versi...
CVE-2024-10150MEDIUM5.4The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs sh...
CVE-2024-9607MEDIUM6.1The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-50583MEDIUM6.3Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to impr...
CVE-2024-48870MEDIUM4.8Sharp and Toshiba Tec MFPs improperly validate input data in URI data registration, resulting in a stored cross-site scr...
CVE-2024-47801MEDIUM6.1Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, resulting in a reflected cross-site scr...
CVE-2024-47549MEDIUM6.1Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow contamination of uninte...
CVE-2024-45842MEDIUM5.3Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability....
CVE-2024-10148MEDIUM5.4The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in...
CVE-2024-9109MEDIUM4.3The WooCommerce UPS Shipping – Live Rates and Access Points plugin for WordPress is vulnerable to unauthorized modificat...
CVE-2024-9686MEDIUM5.3The Order Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a mis...
CVE-2024-10355MEDIUM4.9A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0....
CVE-2024-10354MEDIUM4.9A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this...
CVE-2024-49762MEDIUM4.6Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the ...
CVE-2024-49760MEDIUM5.3OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter...
CVE-2024-49750MEDIUM5.5The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflak...
CVE-2024-49358MEDIUM5.3ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all ...
CVE-2024-10348MEDIUM5.4A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problemat...
CVE-2024-48932MEDIUM5.3ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In versions below 1.5.0, ...
CVE-2024-48426MEDIUM6.2A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz t...
CVE-2024-48425MEDIUM5.5A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the...
CVE-2024-48424MEDIUM5.5A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now