2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9895MEDIUM5.4The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo...
CVE-2024-47944MEDIUM6.8The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin ...
CVE-2024-9944MEDIUM6.1The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This i...
CVE-2024-21535MEDIUM6.1Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property d...
CVE-2024-9969MEDIUM5.4NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert ...
CVE-2024-9952MEDIUM4.8A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects so...
CVE-2024-6757MEDIUM4.3The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Ex...
CVE-2024-9548MEDIUM6.1The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in a...
CVE-2024-9546MEDIUM5.3The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to,...
CVE-2024-30117MEDIUM5.3A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file unde...
CVE-2024-9953MEDIUM4.9A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticate...
CVE-2024-35520MEDIUM6.8Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.
CVE-2024-35519MEDIUM6.8Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in ...
CVE-2024-35518MEDIUM6.8Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.
CVE-2024-48821MEDIUM6.1Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799...
CVE-2024-47885MEDIUM5.4The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to ver...
CVE-2024-48795MEDIUM5.3An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive info...
CVE-2024-48793MEDIUM5.9An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware ...
CVE-2024-48790MEDIUM5.3An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware ...
CVE-2024-47826MEDIUM6.1eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows a...
CVE-2024-47767MEDIUM4.3Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-47766MEDIUM4.9Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46988MEDIUM5.7Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46980MEDIUM4.8Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 1...
CVE-2024-46528MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSp...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now