2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-9115MEDIUM5.4The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ...
CVE-2024-9025MEDIUM5.3The Sight – Professional Image Gallery and Portfolio plugin for WordPress is vulnerable to unauthorized access of data d...
CVE-2024-8872MEDIUM6.1The Store Hours for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of a...
CVE-2024-47337MEDIUM4.3Missing Authorization vulnerability in Phillip Dane Joy Of Text Lite joy-of-text.This issue affects Joy Of Text Lite: fr...
CVE-2024-47044MEDIUM5.3Multiple Home GateWay/Hikari Denwa routers provided by NIPPON TELEGRAPH AND TELEPHONE EAST CORPORATION are vulnerable to...
CVE-2024-8861MEDIUM5.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2024-47145MEDIUM4.3Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels...
CVE-2024-47003MEDIUM6.5Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a str...
CVE-2024-45843MEDIUM5.4Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denyli...
CVE-2024-42406MEDIUM5.4Mattermost versions 9.11.x <= 9.11.0, 9.10.x <= 9.10.1, 9.9.x <= 9.9.2 and 9.5.x <= 9.5.8 fail to properly authorize req...
CVE-2024-6517MEDIUM6.1The Contact Form 7 Math Captcha WordPress plugin through 2.0.1 does not sanitise and escape a parameter before outputtin...
CVE-2024-45836MEDIUM6.1Cross-site scripting vulnerability exists in the web management page of PLANEX COMMUNICATIONS network cameras. If a logg...
CVE-2024-45372MEDIUM6.5MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious pa...
CVE-2024-8803MEDIUM6.1The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use ...
CVE-2024-8723MEDIUM5.4The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in al...
CVE-2024-8552MEDIUM4.3The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability...
CVE-2024-8405MEDIUM5.5An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl...
CVE-2024-46655MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in...
CVE-2024-46488MEDIUM5.5sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability a...
CVE-2024-41445MEDIUM6.5Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the Read...
CVE-2024-20508MEDIUM6.5A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE So...
CVE-2024-20496MEDIUM6.1A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacen...
CVE-2024-20475MEDIUM5.4A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, c...
CVE-2024-20465MEDIUM5.8A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet ...
CVE-2024-20434MEDIUM4.3A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now