2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9384MEDIUM6.1The Quantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site...
CVE-2024-9375MEDIUM6.1The WordPress Captcha Plugin by Captcha Bank plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to...
CVE-2024-9372MEDIUM5.4The WP Blocks Hub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions...
CVE-2024-9368MEDIUM5.4The Aggregator Advanced Settings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads ...
CVE-2024-9353MEDIUM6.1The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg...
CVE-2024-9349MEDIUM6.1The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Sc...
CVE-2024-9345MEDIUM6.1The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting du...
CVE-2024-9237MEDIUM6.1The Fish and Ships – Most flexible shipping table rate. A WooCommerce shipping rate plugin for WordPress is vulnerable t...
CVE-2024-9204MEDIUM6.1The Smart Custom 404 Error Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_SERVER['REQUE...
CVE-2024-8802MEDIUM6.1The Clio Grow plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg witho...
CVE-2024-8520MEDIUM4.3The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-8519MEDIUM5.4The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugi...
CVE-2024-44207MEDIUM4.3This issue was addressed with improved checks. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. Audio messages in Me...
CVE-2024-44204MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in iOS 18.0.1 and iPadOS 18.0.1. A user's save...
CVE-2024-9266MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the ...
CVE-2024-41591MEDIUM6.1DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
CVE-2024-41587MEDIUM5.4Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor31...
CVE-2024-41585MEDIUM6.8DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker ...
CVE-2024-41584MEDIUM4.7DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing vali...
CVE-2024-41583MEDIUM4.7DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due...
CVE-2024-47762MEDIUM5.8Backstage is an open framework for building developer portals. Configuration supplied through APP_CONFIG_* environment v...
CVE-2024-34535MEDIUM5.9In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.
CVE-2024-8508MEDIUM5.3NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRs...
CVE-2024-45872MEDIUM6.3Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient...
CVE-2024-45871MEDIUM6.3Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now