2024 CVE Vulnerabilities

39,257 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8291MEDIUM4.8Concrete CMS versions 9.0.0 to 9.3.3 and below 8.5.19 are vulnerable to Stored XSS in Image Editor Background Color.  A ...
CVE-2024-8267MEDIUM5.4The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable ...
CVE-2024-8103MEDIUM5.4The WP Category Dropdown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter in ...
CVE-2024-8067MEDIUM5.8In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument inject...
CVE-2024-7398MEDIUM5.4Concrete CMS versions 9 through 9.3.3 and versions below 8.5.19 are vulnerable to stored XSS in the calendar event addit...
CVE-2024-47048MEDIUM5.4Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release no...
CVE-2024-46934MEDIUM6.1Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XS...
CVE-2024-41725MEDIUM6.1ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input fields that are used to render pages which may ...
CVE-2024-38324MEDIUM6.5IBM Storage Defender 2.0.0 through 2.0.7 on-prem defender-sensor-cmd CLI does not validate server name during registrati...
CVE-2024-8794MEDIUM5.3The BA Book Everything plugin for WordPress is vulnerable to arbitrary password reset in all versions up to, and includi...
CVE-2024-8628MEDIUM5.4The Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin plugin for WordPress is vulnerable ...
CVE-2024-8738MEDIUM6.1The Seriously Simple Stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_qu...
CVE-2024-8716MEDIUM6.1The XT Ajax Add To Cart for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the ...
CVE-2024-8662MEDIUM6.1The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg ...
CVE-2024-8657MEDIUM5.4The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortc...
CVE-2024-8544MEDIUM6.1The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...
CVE-2024-8432MEDIUM4.3The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modif...
CVE-2024-38269MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel ...
CVE-2024-38268MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG882...
CVE-2024-38267MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG88...
CVE-2024-38266MEDIUM4.9An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG...
CVE-2024-7022MEDIUM4.3Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memor...
CVE-2024-7020MEDIUM4.3Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI...
CVE-2024-7019MEDIUM4.3Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a use...
CVE-2024-8770MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now