2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-41887MEDIUM5.1Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can...
CVE-2024-41886MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker cou...
CVE-2024-41885MEDIUM5.6Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string...
CVE-2024-41884MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker ...
CVE-2024-41883MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR . An attacker...
CVE-2024-41882MEDIUM6.9Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can...
CVE-2024-12622MEDIUM6.4The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'w...
CVE-2024-12594HIGH8.8The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Tempora...
CVE-2024-12405MEDIUM6.1The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in ...
CVE-2024-12210MEDIUM4.3The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of da...
CVE-2024-12100MEDIUM6.1The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due t...
CVE-2024-12096MEDIUM6.1The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it b...
CVE-2024-12034MEDIUM5.3The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, ...
CVE-2024-11885MEDIUM6.4The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njte...
CVE-2024-12710MEDIUM6.1The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versi...
CVE-2024-12617MEDIUM5.4The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability c...
CVE-2024-12518MEDIUM6.4The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' sho...
CVE-2024-12507MEDIUM6.4The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' ...
CVE-2024-12266MEDIUM6.5The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due...
CVE-2024-9427MEDIUM5.4A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link ...
CVE-2024-47515HIGH8.1A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the di...
CVE-2024-12582HIGH7.1A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metri...
CVE-2024-53961HIGH8.1ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Di...
CVE-2024-56363HIGH7.8APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed fo...
CVE-2024-56362MEDIUM5.5Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now