2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-25691MEDIUM6.1There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 11.1 and below which may allow a remote, unaut...
CVE-2024-46409MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in SeedDMS v6.0.28 allows attackers to execute arbitrary web scripts o...
CVE-2024-47765MEDIUM6.1Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential c...
CVE-2024-9410MEDIUM5.3Ada.cx's Sentry configuration allowed for blind server-side request forgeries (SSRF) through the use of a data scraping ...
CVE-2024-9484MEDIUM5.5An null-pointer-derefrence in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on Ma...
CVE-2024-9483MEDIUM5.5A null-pointer-dereference in the signature verification module in AVG/Avast Antivirus signature <24092400 released on 2...
CVE-2024-9482MEDIUM5.5An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ...
CVE-2024-9481MEDIUM5.5An out-of-bounds write in the engine module in AVG/Avast Antivirus signature <24092400 released on 24/Sep/2024 on MacOS ...
CVE-2024-8499MEDIUM6.1The Checkout Field Editor (Checkout Manager) for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site ...
CVE-2024-47657MEDIUM6.5This vulnerability exists in the Shilpi Net Back Office due to improper access controls on certain API endpoints. An aut...
CVE-2024-47653MEDIUM6.5This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for modification and cancellation requ...
CVE-2024-47651MEDIUM6.5This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint...
CVE-2024-9271MEDIUM5.4The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ...
CVE-2024-9071MEDIUM5.4The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2024-9435MEDIUM6.1The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via U...
CVE-2024-9306MEDIUM4.8The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all vers...
CVE-2024-6444MEDIUM6.5No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client....
CVE-2024-9242MEDIUM5.4The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'me...
CVE-2024-8804MEDIUM5.4The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functiona...
CVE-2024-6443MEDIUM6.5In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is e...
CVE-2024-6442MEDIUM6.5In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
CVE-2024-47855MEDIUM5.3util/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.
CVE-2024-47854MEDIUM6.1An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitra...
CVE-2024-9445MEDIUM5.4The Display Medium Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's display_medi...
CVE-2024-9421MEDIUM5.4The Login Logout Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' parameter i...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now