2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8990MEDIUM6.4The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's geo_mashup_visible_pos...
CVE-2024-8989MEDIUM6.4The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress i...
CVE-2024-8728MEDIUM6.1The Easy Load More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8727MEDIUM6.1The DK PDF plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without ...
CVE-2024-8720MEDIUM6.4The RumbleTalk Live Group Chat – HTML5 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2024-8718MEDIUM6.1The Gravity Forms Toolbar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter i...
CVE-2024-8675MEDIUM4.3The Soumettre.fr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability che...
CVE-2024-8632MEDIUM6.5The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and mo...
CVE-2024-8107MEDIUM5.4The Slider Revolution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all vers...
CVE-2024-21531MEDIUM5.3All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigat...
CVE-2024-0116MEDIUM6.5NVIDIA Triton Inference Server contains a vulnerability where a user may cause an out-of-bounds read issue by releasing ...
CVE-2024-9358MEDIUM5.9A vulnerability has been found in ThingsBoard up to 3.7.0 and classified as problematic. Affected by this vulnerability ...
CVE-2024-47396MEDIUM5.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moveaddons Move Ad...
CVE-2024-45073MEDIUM4.8IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a p...
CVE-2024-28807MEDIUM6.5An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @C...
CVE-2024-28810MEDIUM6.6An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT...
CVE-2024-46635MEDIUM5.9An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access se...
CVE-2024-35495MEDIUM4.3An Information Disclosure vulnerability in the Telemetry component in TP-Link Kasa KP125M V1.0.0 and Tapo P125M 1.0.0 Bu...
CVE-2024-9158MEDIUM4.6A stored cross site scripting vulnerability exists in Nessus Network Monitor where an authenticated, privileged local at...
CVE-2024-47536MEDIUM5.4Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo rig...
CVE-2024-46548MEDIUM6.3TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eave...
CVE-2024-46540MEDIUM6.3A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attacke...
CVE-2024-45993MEDIUM6.5Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.
CVE-2024-47532MEDIUM6.5RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to prote...
CVE-2024-47530MEDIUM6.1Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users b...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now