2024 CVE Vulnerabilities

39,224 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9979MEDIUM5.3A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or ...
CVE-2024-48948MEDIUM4.8The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if t...
CVE-2024-9977MEDIUM5.1A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected ...
CVE-2024-48278MEDIUM5.5Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) v...
CVE-2024-49384MEDIUM4.3Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products ...
CVE-2024-49383MEDIUM4.3Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products a...
CVE-2024-49382MEDIUM4.3Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products ...
CVE-2024-47674MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in er...
CVE-2024-9895MEDIUM5.4The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo...
CVE-2024-47944MEDIUM6.8The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin ...
CVE-2024-9944MEDIUM6.1The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This i...
CVE-2024-21535MEDIUM6.1Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property d...
CVE-2024-9969MEDIUM5.4NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert ...
CVE-2024-9952MEDIUM4.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so...
CVE-2024-6757MEDIUM4.3The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Ex...
CVE-2024-9548MEDIUM6.1The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in a...
CVE-2024-9546MEDIUM5.3The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to,...
CVE-2024-30117MEDIUM5.3A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde...
CVE-2024-9953MEDIUM4.9A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticate...
CVE-2024-35520MEDIUM6.8Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2024-35519MEDIUM6.8Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in ...
CVE-2024-35518MEDIUM6.8Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
CVE-2024-48821MEDIUM6.1Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799...
CVE-2024-47885MEDIUM5.4The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to ver...
CVE-2024-48795MEDIUM5.3An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive info...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now