2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8432MEDIUM4.3The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif...
CVE-2024-38269MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel ...
CVE-2024-38268MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG882...
CVE-2024-38267MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG88...
CVE-2024-38266MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG...
CVE-2024-7022MEDIUM4.3Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor...
CVE-2024-7020MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI...
CVE-2024-7019MEDIUM4.3Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use...
CVE-2024-8770MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server...
CVE-2024-44540MEDIUM6.6Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command s...
CVE-2024-43201MEDIUM5.9The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker...
CVE-2024-39843MEDIUM6.7A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL comm...
CVE-2024-39342MEDIUM6.6Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier use...
CVE-2024-39341MEDIUM5.9Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and...
CVE-2024-9014MEDIUM6.5pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows ...
CVE-2024-40441MEDIUM6.6An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pi...
CVE-2024-47069MEDIUM6.1Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy set...
CVE-2024-47068MEDIUM6.1Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobber...
CVE-2024-23972MEDIUM6.8Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability all...
CVE-2024-23933MEDIUM6.8Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows p...
CVE-2024-23922MEDIUM6.8Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows p...
CVE-2024-46241MEDIUM5.9PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in...
CVE-2024-46544MEDIUM5.9Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem...
CVE-2024-8903MEDIUM4.7Local active protection service settings manipulation due to unnecessary privileges assignment. The following products a...
CVE-2024-8758MEDIUM4.8The Quiz and Survey Master (QSM) WordPress plugin before 9.1.3 does not sanitise and escape some of its settings, which...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now