2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-6985MEDIUM4.4A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnera...
CVE-2024-5474MEDIUM5.5A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning softwar...
CVE-2024-47507MEDIUM6.9An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne...
CVE-2024-47501MEDIUM6.8A NULL Pointer Dereference vulnerability in the packet forwarding engine (pfe) of Juniper Networks Junos OS on MX304, ...
CVE-2024-47496MEDIUM6.8A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a loc...
CVE-2024-47489MEDIUM6.9An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networ...
CVE-2024-39544MEDIUM5.1An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved ...
CVE-2024-39534MEDIUM5.4An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows ...
CVE-2024-39527MEDIUM6.8An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Junip...
CVE-2024-47875MEDIUM6.1DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to n...
CVE-2024-47830MEDIUM5.8Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostn...
CVE-2024-25622MEDIUM4.3h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers...
CVE-2024-8530MEDIUM5.9CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data whe...
CVE-2024-6657MEDIUM6.5A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuo...
CVE-2024-9856MEDIUM4.8A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this ...
CVE-2024-9616MEDIUM6.1The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-9611MEDIUM6.1The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-9610MEDIUM6.1The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_a...
CVE-2024-9587MEDIUM4.3The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-9586MEDIUM5.3The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o...
CVE-2024-9543MEDIUM6.4The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl...
CVE-2024-9538MEDIUM6.5The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including...
CVE-2024-9507MEDIUM4.9The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form buil...
CVE-2024-9436MEDIUM6.1The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulner...
CVE-2024-9346MEDIUM6.1The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' pa...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now