2024 CVE Vulnerabilities

39,225 CVEs published in 2024.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2024-8472MEDIUM6.1Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t...
CVE-2024-8471MEDIUM6.1Cross-Site Scripting (XSS) vulnerability, whereby user-controlled input is not sufficiently encrypted. Exploitation of t...
CVE-2024-8462MEDIUM6.3A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of...
CVE-2024-8461MEDIUM5.3A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part ...
CVE-2024-8460MEDIUM5.9A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue i...
CVE-2024-7605MEDIUM4.3The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2024-7381MEDIUM5.3The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization a...
CVE-2024-7380MEDIUM4.3The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability c...
CVE-2024-5956MEDIUM5.3This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the ...
CVE-2024-6929MEDIUM5.4The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ param...
CVE-2024-6894MEDIUM5.4The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5...
CVE-2024-6332MEDIUM6.5The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unaut...
CVE-2024-8363MEDIUM5.4The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shor...
CVE-2024-5309MEDIUM5.4The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modifi...
CVE-2024-45107MEDIUM5.5Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After F...
CVE-2024-6835MEDIUM5.3The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up...
CVE-2024-6846MEDIUM5.3The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an una...
CVE-2024-45429MEDIUM6.1Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Field...
CVE-2024-2166MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email S...
CVE-2024-20506MEDIUM6.1A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2...
CVE-2024-45399MEDIUM6.1Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indi...
CVE-2024-45172MEDIUM6.8An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanism...
CVE-2024-45008MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting to...
CVE-2024-45007MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work i...
CVE-2024-45006MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: xhci: Fix Panther point NULL pointer deref at full-...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now